generated: '2026-07-19' method: searched source: https://www.kry.se/en/information-on-data-ai/ note: 'KRY | LIVI publishes no public API, so this file records regulatory and data-protection conformance rather than API/technical standards. Technical standards below are marked unknown because there is no public specification, developer portal or reference to evidence them — not because they were evaluated and failed.' standards: - id: cqc-registration conforms: true evidence: 'Livi (UK) is regulated by the Care Quality Commission and states "Rated Good by the Care Quality Commission"' source: https://www.livi.co.uk/about/ - id: gdpr conforms: true evidence: Published privacy notice with a named Data Protection Officer contact (privacy@kry.se) and EU data-residency commitments source: https://www.kry.se/en/legal/privacy-policy/ - id: eu-data-residency conforms: true evidence: '"Data is stored in security certified data centres in the EU."' source: https://www.kry.se/en/information-on-data-ai/ - id: encryption-in-transit-and-at-rest conforms: true evidence: '"Video calls are protected by strong encryption in transit and at rest."' source: https://www.kry.se/en/information-on-data-ai/ - id: swedish-patient-data-act conforms: true evidence: Patient information is stated to be protected by confidentiality under the Swedish Patient Safety Act (2010:659) source: https://www.kry.se/en/legal/privacy-policy/ - id: coordinated-vulnerability-disclosure conforms: true evidence: Published vulnerability disclosure policy with safe-harbour terms, scope and response targets source: https://www.kry.se/vulnerability-disclosure/ - id: bankid conforms: true evidence: Swedish patient authentication is performed with BankID source: https://www.kry.se/en/ - id: iso-27001 conforms: unknown evidence: No ISO 27001 certification is claimed on any public KRY or Livi page; the data page refers only to "security certified data centres" - id: soc-2 conforms: unknown evidence: not published - id: hl7-fhir conforms: unknown evidence: no public API or interoperability documentation published - id: oauth2 conforms: unknown evidence: no public API or OpenAPI specification published - id: rfc9457-problem-details conforms: unknown evidence: no public API or OpenAPI specification published