SECURITY OVERVIEW
Pending legal reviewSecurity boundaries before security claims.
This overview separates visible showcase safeguards from controls that still require technical, contractual, and independent review.
Current showcase boundary
The public demo is anonymous and separate from protected administrator access. The showcase should not receive real patient data, file uploads, live EHR connections, production OAuth credentials, or production clinical workflows.
Access and least privilege
Administrator access uses an authenticated, server-authorized flow. Organization verification, formal role matrices, periodic access certification, and workforce procedures remain pending operational validation.
Data protection
Encryption standards, key management, backup recovery, production logging, vulnerability management, penetration testing, and secure-development controls are pending documented verification. No certification is claimed.
Research safeguards
Research is designed around aggregate feasibility, organization isolation, explicit approval, pseudonymous outputs, purpose-bound access, expiry, revocation, and audit history. Pseudonymous data is not anonymous data.
Incident readiness
Monitoring views and an incident history surface are present in the protected workspace. Severity definitions, notification duties, response ownership, evidence preservation, and post-incident review remain pending legal and operational approval.
Report a concern
Use the incident-reporting instructions. Do not send patient data, passwords, access tokens, or exploit details that could increase harm in an initial email.
Last updated August 4, 2026. Placeholder text is not a final legal notice, contract, certification, or compliance claim.
