Cyberattack
Ransomware encrypts the servers and the network is isolated for the investigation: no access to patient records, sometimes for weeks.
CARYLIA SafeVault keeps a readable copy of patient documents inside the facility: on an appliance installed on your premises, and right down to the care workstations. Cyberattack, EHR outage, network failure: care teams keep reading reports, prescriptions and results.
Product developed and proven in the lab; we are opening supported pilots in Belgium and France.

As soon as the electronic health record becomes unavailable, reports, prescriptions and results can no longer be read. Clinical decisions go on — without history, rebuilt over the phone, on paper or from memory, and with no record of who looked at what.
Ransomware encrypts the servers and the network is isolated for the investigation: no access to patient records, sometimes for weeks.
An application bug, a failed update, an unavailable database: the documents exist, but nothing displays them any more.
Telecom link, core network, a failure in a technical room: the care workstation can no longer reach the server.
Planned work takes longer than expected, while care goes on.
Sources: French Digital Health Agency (ANS) / CERT Santé, observatory of information-system security incident reports for the health and social-care sectors, 2025 report; Directive (EU) 2022/2555 (NIS2), Article 21.
SafeVault replaces neither the patient record nor archiving: it keeps a readable copy of the documents that matter for the day the main system stops responding. A limited scope, a short deployment, and coexistence designed in from the start.
A Debian virtual machine, installed from an ISO image on your hypervisor (Hyper-V, VMware, Proxmox, Nutanix). Data volume encryption, encrypted backups, signed updates with automatic rollback. Data never leaves the facility.
A Windows service keeps, on each critical workstation — emergency department, on-call physician, nursing station — an encrypted cache of its unit’s documents. With the network down or the appliance stopped, the clinician opens the workstation portal, finds the patient and reads the document.
Patient search and reading for clinicians; sources, accounts, monitoring and audit for IT. Day-to-day operation happens in the browser, with no SSH access to the appliance. The console is currently in French; English and Dutch are planned.
What makes the difference with a file copy: documents readable without a network, attached to the right patient, under traced access — and monitoring that tells the truth.
Each critical workstation keeps an encrypted cache of its unit’s documents, and shows how long ago it last synchronised.
Documents arrive through the feeds your applications already produce — HL7, FHIR, file drops — with no re-keying.
Identity comes from the HIS message (local patient ID, national identifier when the source provides it); when a source only provides a file name, clinicians see exactly that, not a false certainty.
Clinicians only see documents from the care units they are entitled to, on the workstation as in the console.
Append-only log, HMAC-chained with a key held outside the database: any change or deletion shows, and raises an alert.
It reports nothing it has not observed: an orphaned drop folder, a workstation no longer receiving, a stopped HL7 listener are visible before the day of the outage.
Documents arrive continuously from existing applications; the appliance files them under the right patient and redistributes them to care workstations. On the day of the outage, each link works without the previous one: the workstation reads its cache even if the appliance is not responding.

Virtual machine on your hypervisor • local data
The appliance measures its own posture: a dated security score computed on around fifteen criteria checked on the machine itself, capped as long as a critical criterion fails. The security dossier given to the CISO describes each mechanism — and its known limitations.
LUKS2 data volume on the appliance; AES-256-GCM cache on Edge workstations, unreadable without a successful login.
HTTPS for the console and workstations, server certificate pinned on the Edge side; HL7 MLLP over TLS, mutual TLS if needed.
Named accounts, TOTP two-factor authentication enforceable per account, lockout after failures, short sessions closed at every restart.
HMAC-SHA256 chained log with a key held outside the database, append-only at database level, checked daily: tampering raises a critical alert.
Ed25519-signed packages, backup and automatic rollback; workstation agent Authenticode-signed and verified before installation.
No outbound traffic to the vendor, HL7 listener closed by default, SSH can be disabled from the console, host firewall.
SafeVault contributes to your compliance effort; it does not replace it. Certifications apply to organisations — hosting providers, healthcare facilities —, not to software.
In Belgium as in France, SafeVault is for organisations whose care goes on when the information system stops.
Emergency departments, wards, on-call physicians: critical workstations keep their unit’s documents.
Hospital networks in Belgium, GHTs in France: one deployment per facility, shared rules.
Nursing and care homes: residents’ essential documents remain readable during an outage.
Reports and results as PDF, received over HL7, FHIR or secure file drop. DICOM imaging is not covered.
The product is developed and proven in the lab; the next step is the test of real life. A pilot covers one unit and a few workstations, for three to six months. It is free of charge and carries no purchase commitment.
Choice of unit, workstations and sources; IT, CISO, DPO and nursing leads; pilot agreement.
The appliance on your hypervisor: two virtual disks, data volume encryption, TLS certificate.
Care units, named accounts with two-factor authentication, document sources, retention periods.
The signed agent installed on the selected workstations, approved one by one in the console.
We simulate the information system going down: do clinicians find the documents they need, and how fast?
Measurement against the criteria set at the start, then a decision: uninstall, or move to production.
CARYLIA designs and publishes SafeVault. The company is being incorporated in Wallonia, Belgium, and targets healthcare facilities in Belgium and France.
The product grew out of an engineer’s observation: when a cyberattack or an outage hits, continuity of care still relies on paper, the phone and home-made scripts. SafeVault is designed, built and tested by its founder, an engineer, through successive releases each shipped with its own acceptance test plan.
facilities interested in a pilot, integrators and sector partners, incubators and support organisations, seed investors.
Get in touchFour working documents, sent on request with the product version they describe. They are currently written in French; tell us in the form which ones you need.
What SafeVault does, what it is not, and how a pilot unfolds.
Request the documentArchitecture, ports and flows, encryption, authentication, audit, updates — and known limitations.
Request the documentProcessing, retention periods, roles: material for your record of processing and your DPIA.
Request the documentMutual commitments, duration, data, end of the pilot.
Request the documentNo. Everything is installed on your premises: no telemetry, no outbound call to the vendor. The licence is a signed file, verified offline.
Through the feeds your applications already produce: HL7 v2 (MDM) messages over MLLP, FHIR R4 connector, SFTP drop with a dedicated account, HTTPS drop with an API key, or a watched folder. Documents are PDFs.
Identity is taken from the HIS message: local patient ID, plus the national identifier when the source provides it — INS in France, NISS in Belgium, whose check digits are verified. When a source only provides a file name, clinicians see it displayed as such: SafeVault does not show a certainty it does not have.
The licence never stops care: thirty days of grace with no restriction, after which only adding accounts, sources or workstations is suspended. Reading, synchronisation and ingestion go on. The stack relies on standard components (Debian, PostgreSQL, Docker).
Encrypted volume, an audit trail that reveals any tampering, encrypted backups restorable on a fresh machine — and care workstations that keep serving their cache without the appliance.
No, and that is deliberate: the appliance is a Linux virtual machine installed from an image, for reproducible and reversible updates. A VM on your hypervisor is all it takes. Care workstations, on the other hand, run Windows.
Security logs are sent as RFC 5424 syslog over TLS to your collector. Alerts can also be sent by email or webhook.
Not in production yet: we are opening the first pilots. You will not be the twentieth customer of a frozen product; you will be among the first to shape its priorities.
On quotation, after scoping: the number of units, critical workstations and sources to connect varies too much between facilities for a list price. The pilot is free of charge.
A one-hour demo by video call or on your infrastructure, scoping a pilot, the pilot kit, or a conversation about the company: tell us what would help. We answer in English or French.
An acknowledgement is sent as soon as you submit the form.
A technical conversation, with no sales intermediary.
The demo runs on fictitious data.
Describe your organisation, your role and your request; we will get back to you to arrange a first conversation.