Regulators, auditors and IT staff · C0488
Which security findings remain open?
In the pilot (v0.2.0, synthetic data)
Short answer
Among them: a demo signing key kept in the repository, password hashing below the design target, no key rotation, compartments as flags rather than a consent engine, an audit chain that is not write-once, and no per-address rate limit.
This exists in the synthetic-data pilot only.
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- What tests exist? Pilot
- Can the pilot hold real patient data? No claim
- Is a penetration test scheduled? Open
- Can we see an audit report? No claim
See it in context: For auditors and IT · Search the help center · Ask a question