[PLACEHOLDER — to be completed by the client: scope, HDS/security constraints, outcome.]
[PLACEHOLDER — verify communication rights before publishing. Describe the scope, compliance constraints, and achieved results.]
We design, take over, and modernise high-performance healthcare applications that comply with GDPR and are hosted on HDS-certified infrastructure — no AI-washing.
Highly sensitive patient data, HDS and GDPR requirements, legacy or no-code applications at breaking point, and a constant tension between time-to-market and compliance. Building for healthcare means delivering on both.
Patient records, imaging, results: the slightest leak compromises your liability and the trust of healthcare professionals. Security is not a luxury—it’s the foundation.
Certified health data hosting, access traceability, consent, right to erasure: the framework is strict, and it evolves. Better to build it in from the start.
Ageing business applications or no-code tools that can no longer handle the load or business rules: technical debt slows down teams and patients.
Operations want to deliver, compliance wants to secure. We refuse to choose: clear scoping, incremental delivery, security and compliance built in from the first line of code.
From bespoke solutions to legacy system overhauls, every intervention is grounded in the same principles: compliance, sovereignty, and a transfer of skills that keeps you independent.
Web and mobile, offline mode, care and patient pathways. Designed for the field, built for audits—not the other way around.
Application developmentMoving from a struggling no-code or legacy system to maintainable code, hosted in France. Gradual transition, with zero service disruption.
No-code to code migrationLeverage your internal data (protocols, reports) with sovereign or on-premise models. Human oversight at every step—your code stays in-house.
AI assistants connected to your dataNo-code or “vibe-coded” application to take over: audit, data security, migration to maintainable and compliant foundations.
Project takeoverFor a healthcare institution, the real question isn’t “does it work?” but “where does my data go, who accesses it, and can I leave?”. Here are our answers, clearly, without jargon.
Your health data is hosted in France, on HDS-certified infrastructure (OVH, Scaleway). Depending on your needs: managed mode, or self-hosting under your institution’s direct control.
No reliance on non-European cloud. Your patients’ data stays in France—this is the starting point, not an option.
Data minimisation, traceable consent, right to erasure, processing register: RGPD is built in from the start, never added as an afterthought.
Row-Level Security at the database level: every access is filtered by role and institution. Data separation isn’t just application-level—it’s embedded in the engine.
Data used for management or research is anonymised or pseudonymised based on use. Identifying data does not circulate without reason.
The code is yours, the data is exportable, the hosting is transferable. You’re never locked in with Scroll.
From hospital systems to medical imaging—three concrete examples, not promises.
[PLACEHOLDER — verify communication rights before publishing. Describe the scope, compliance constraints, and achieved results.]
Migration from Bubble to Next.js 15 + Supabase, self-hosted with OVH. Reversible switch, cabinet by cabinet, with no disruption to care services.
protectus.eco ↗Web and mobile medical application (iOS/Android) with offline mode and PDF generation. Deep pelvic endometriosis scoring; anonymised data processed by region.
Modern, maintainable, and recruit-ready. Above all, fully traceable: every access is logged, every deployment is tested.
The most frequent questions we address when scoping projects with healthcare institutions or healthtech startups.