Why SecuSteri is a compliance tool

Sterilization traceability is not just record-keeping — it's a legal obligation with precise requirements. SecuSteri is designed to meet them.

What Spanish law requires — and how SecuSteri meets it

In Spain, sterilization regulations apply across all 17 Autonomous Communities to professions that use reusable instruments. Dental clinics must comply with Royal Decree 1594/1994, which requires systematic sterilization as a basic operating condition. Tattoo, piercing, and permanent makeup studios are regulated by autonomous community decrees in each of the 17 regions. Podiatrists, regulated as an independent health profession under Law 44/2003 (LOPS — Ley de Ordenacion de las Profesiones Sanitarias), are held to the same sterilization standards as dental clinics. The UNE-EN 13060 standard defines technical requirements for the small autoclaves used in these professions. SecuSteri is designed to cover the compliance needs of every regulated profession in Spain.

Tamper-proof sterilization register

Spanish regulations require a record for each sterilization cycle demonstrating that parameters have been validated. The Consejeria de Sanidad (Regional Health Authority) in each Autonomous Community evaluates the quality of records during inspections. SecuSteri generates a traceability record for each cycle, digitally signed by the operator with their PIN code. Once signed, the record is locked — no modifications are possible. It is the digital equivalent of a dedicated logbook, without the risks of fading thermal printouts or illegible handwriting.

Instrument-cycle traceability

Autonomous community regulations and Royal Decree 192/2023 (implementing the EU Medical Devices Regulation) require complete traceability from the autoclave to the patient. SecuSteri goes further: every sterilized instrument is linked to its cycle, operator, container, and use-by date. The traceability chain is complete and verifiable — from the autoclave cycle to the patient record.

Append-only audit trail

Every significant action in SecuSteri is recorded in a tamper-proof audit log: who did what, when, and on which record. This log is append-only — technically impossible to modify or delete, even by an administrator. In the event of a Consejeria de Sanidad inspection, or a disciplinary proceeding by a professional college, the complete history of operations is available.

Digital PIN signing

Each operator signs cycles with their personal 4-digit PIN code. This signature individually identifies the person responsible for validating the cycle — essential for professional accountability. The PIN is stored as a cryptographic hash (bcrypt) — even the SecuSteri administrator cannot read it.

Triple validation: physical, chemical, and biological controls

The UNE-EN 13060 standard and Spanish best-practice guidelines require three levels of control: physical (cycle parameters), chemical (indicators), and biological (spore tests). SecuSteri tracks autoclave checks — vacuum, Bowie-Dick, Helix, biological — linked to each device, with date and result. During an inspection, the complete check history for each autoclave is available instantly.

Compliant data retention

Spanish regulations require keeping sterilization records for a minimum of 5 years for clinical records (Law 41/2002 — Ley Basica Reguladora de la Autonomia del Paciente) and variable periods under autonomous community decrees for tattoo and piercing. SecuSteri automatically retains your data according to your plan duration: 5 years (Standard), 10 years (Pro), unlimited (Clinic+). No risk of loss, fire, or water damage. Your sterilization history is always accessible — whether for a Consejeria de Sanidad inspection, a professional college proceeding, or your own quality assurance.

Hosted in the EU, GDPR compliant

Your data is hosted in the European Union on the Scaleway Paris infrastructure. Spain, as an EU member state, is fully covered by the GDPR — EU hosting meets all data residency requirements. The transfer between your browser and our servers is encrypted (TLS). Data at rest is encrypted. SecuSteri is GDPR compliant: right of access, right to data portability, right to erasure. We never sell your data and never use it for advertising purposes.

Data export at any time

You can request a complete export of all your data (cycles, instruments, autoclaves, audit log) as a zipped CSV archive, delivered by email. The export covers your plan's retention window. Your data belongs to you — you can retrieve it at any time.

SecuSteri vs the paper register

The paper register remains the standard in many Spanish practices. But paper records present documented risks: missing pages, illegible handwriting, forgotten entries after a rushed cycle, inability to search quickly, and no backup in case of disaster. Thermal printouts from autoclaves fade over time. With 17 Autonomous Communities that can inspect independently, and penalties reaching up to 601,012 euros under Law 14/1986 (Ley General de Sanidad), having digital records instantly accessible from any device is a decisive advantage. SecuSteri eliminates these risks by digitizing the entire process while meeting the same professional obligations.

Simple pricing, from €29/month excl. VAT

One plan for solo professionals, one for growing teams, one for multi-site organizations. Cancel anytime.