Architecture

Built to be verified.

No marketing on this page. What runs, where it runs, how data is separated, and which standards it meets. Written for CTOs and system administrators.

Everything in the browser. Nothing on workstations.

ZenRIS runs entirely in the browser: scheduling, worklist, reporting, dictation and the diagnostic viewer. A new workstation means a browser and a URL — no client to install, no hardware dongle, no per-workstation licensing.

Updates are applied once, on the server. The next morning, every workstation runs the same version, because there are no local versions to synchronize. Even reporting to CNAS (Romania's national health insurance house) needs no desktop: ZenAgent submits the claim automatically, from the server — no SIUI (the legacy desktop reporting app) installed on any workstation, no manual exports.

For physicians who prefer a locally installed viewer, there is ZenView Desktop. It's an option, not a requirement.

Every institution gets its own archive.

A ZenRIS tenant can hold several institutions — a hospital, two clinics, a satellite site. Each institution has its own PACS archive: its studies live in its archive, with its users and its permissions.

This is not filtering on a shared database. A filter is a query that can be written wrong; a separate archive has nothing to leak. The separation is architectural, so a configuration mistake in one institution cannot expose another's studies.

The audit log records access per institution. When someone asks “who saw this study”, you answer with an export, not a guess.

On-premise or cloud. The same product.

Same codebase, same modules, same features. Choosing between on-premise and cloud is an operating decision, not a product decision: there is no “cloud version” with extra features, and no “on-premise version” lagging behind.

The real differences are three, all operational:

  • Where the data lives. On-premise: on your servers, in your network. Cloud: in data centers in the European Union, with a Romania hosting option.
  • Who runs the infrastructure. On-premise: your IT team, with our support for installation and updates. Cloud: us — servers, monitoring, backups.
  • How you start. On-premise: we size it together and install on your servers. Cloud: you get your tenant and URL, then set up institutions and users.
  • What doesn't differ. The modules, the interface, the release cadence. Data stays in standard formats, so neither option locks you in.

Security is a checklist, not a claim.

The list below is not brochure copy. It's the list your team can verify point by point at the demo, with test accounts.

  • 2FA. A second factor at login, for any account.
  • SSO. Integration with your existing directory: AD/LDAP, SAML/OIDC. Accounts are managed where you already manage them.
  • Encryption. In transit and at rest.
  • Backup and DR. Scheduled backups and a restore procedure you can test, not just read.
  • Audit log. Complete and exportable: who, what, when — every data access, available for internal or external audit.

Native DICOM, spoken plainly.

ZenRIS speaks DICOM in both directions, with no translators in between. The RadiAnt, OsiriX and Horos integrations are exactly that: external desktop viewers connecting to the archive over standard DICOM. Physicians keep their tools. The archive stays one.

Concretely:

  • Worklist. The modality gets its worklist straight from the schedule. The operator doesn't retype the patient's name at the console — the data comes from ZenPlan, with no typing errors.
  • Store. Acquired images enter the institution's archive automatically, attached to the correct study, at the moment of acquisition.
  • Query/Retrieve. Any DICOM-compatible workstation or application can search the archive and pull studies — including the desktop viewers physicians already use.

Compliance with documents, not adjectives.

ZenRIS is a Class I medical device, registered with ANMDMR, Romania's medical device authority. For software used in medical care in Romania, that's not a footnote — it's the starting point.

Patient data is processed under GDPR, hosted in the European Union or in Romania — or on your own servers, if you choose on-premise. The complete audit log backs the accountability obligation: who accessed what is demonstrated with an export, not asserted in an email.

Bring your IT team to the demo.

The demo runs in the browser, like the rest of the product. Come with your network administrator, your security officer and your list of uncomfortable questions. We'd rather answer them before the contract than after.