Big Picture Medical · Trust Center

Big Picture Medical Trust Center

Trust center

Big Picture Medical maintains a public trust center documenting ISO/IEC 27001:2022, Cyber Essentials, HIPAA, GDPR, and WCAG 2.1 AA compliance.

CompanyHealthcareHealth CareElectronic Health RecordsopenEHRFHIRHL7InteroperabilityClinical DataCare PathwaysWorkflowOrchestrationNo CodeNHSUnited Kingdom
Trust center: https://trust.bigpicturemedical.com/

Certifications & Compliance

ISO/IEC 27001:2022Cyber EssentialsHIPAAGDPRWCAG 2.1 AA

Source

Trust Center

big-picture-medical-trust-center.yml Raw ↑
generated: '2026-09-02'
method: searched
probe: true
source: https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/544327769943197
url: https://trust.bigpicturemedical.com/
platform: SafeBase (CNAME bigpicturemedical.portals.safebase.io)
url_status: 403
url_status_note: >-
  The trust centre is real and linked from the footer of every page on
  bigpicturemedical.com, but it sits behind a Cloudflare bot interstitial that answered
  HTTP 403 "Just a moment..." to our fetch, including at the portal's own SafeBase
  hostname. That is an ordinary edge policy turning away a crawler, not a dead page — the
  DNS record, the CNAME to SafeBase's portal service and the site-wide footer link all
  establish that the page exists. Its CONTENTS were therefore not read by us. Every
  certification listed below is taken instead from two documents we did fetch at 200: the
  company's own homepage badge row and its G-Cloud 14 Digital Marketplace listing.
certifications:
- ISO/IEC 27001:2022
- Cyber Essentials
- HIPAA
- GDPR
- WCAG 2.1 AA
certification_detail:
- name: ISO/IEC 27001
  status: certified
  accreditor: UKAS
  accreditation_date: '2022-07-05'
  scope: >-
    "Provision of a SaaS-based intelligent pathway technology to support collaborative
    healthcare delivery and clinical research within the healthcare eco-system"
  source: https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/544327769943197
- name: Cyber Essentials
  status: certified
  source: https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/544327769943197
- name: Cyber Essentials Plus
  status: claimed-on-website-but-answered-No-on-G-Cloud-14
  note: >-
    bigpicturemedical.com's homepage badge row advertises "Cyber Essentials Plus —
    Independently audited". The company's G-Cloud 14 submission (May 2024) answers "Cyber
    essentials plus: No". Recorded as a discrepancy, not resolved in either direction.
  sources:
  - https://www.bigpicturemedical.com/
  - https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/544327769943197
- name: HIPAA Seal of Compliance
  status: claimed
  source: https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/544327769943197
- name: PCI DSS
  status: not certified
  source: 'G-Cloud 14: "PCI certification: No"'
- name: CSA STAR
  status: not certified
  source: 'G-Cloud 14: "CSA STAR certification: No"'
- name: SOC 2
  status: not claimed anywhere we could read
security_program:
  penetration_testing: at least once a year, "IT Health Check" performed by a CHECK service provider
  access_restriction_testing: at least every 6 months
  data_at_rest: encrypted at rest using cloud-provider managed functionality with application-specific keys
  data_in_transit: TLS 1.2 or above, buyer-to-supplier and within the supplier network
  data_location: United Kingdom
  authentication: 2-factor authentication for users; RBAC plus MFA and VPN-limited environment access for management interfaces
  governance: >-
    Named board-level person responsible for service security; ISMS Management Review Board
    and an InfoSec & Privacy Working Group reporting to it; regular internal audits; staff
    attestation to key policies on commencement.
  vulnerability_management: >-
    Automated continuous monitoring of project dependencies for known vulnerabilities, with
    automatic pull requests to update affected dependencies and integrated security
    advisories. Conforms to a recognised standard per the G-Cloud answer.
  secure_development: independent review of processes (ISO/IEC 27034 / ISO/IEC 27001 / CSA CCM v3.0 class)
  log_retention: at least 12 months for user, supplier and system audit data
vulnerability_disclosure:
  published: false
  note: >-
    No coordinated vulnerability disclosure surface was found. /.well-known/security.txt
    404s, /security 404s, and no HackerOne, Bugcrowd or Intigriti program could be located.
    A published security.txt with a Contact and Policy line is the cheapest single fix
    available here. No Security or VulnerabilityDisclosure pointer is emitted.
evidence:
- source: https://www.bigpicturemedical.com/
  status: 200
  keywords: [Cyber Essentials, Cyber Essentials Plus, G-Cloud, GDPR, HIPAA, 'ISO/IEC 27001:2022', Trust Centre]
- source: https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/544327769943197
  status: 200
  keywords: ['ISO/IEC 27001', UKAS, Cyber essentials, HIPAA Seal of Compliance, CHECK]
- source: https://trust.bigpicturemedical.com/
  status: 403
  keywords: []
  note: Cloudflare bot challenge; contents not read

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/big-picture-medical-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.