AuroraMed v0.2.0 is a synthetic-data pilot. See exactly what's built →

Regulators, auditors and IT staff

For auditors and IT

Evidence, documentation and open findings.

How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration

C0486Can we see an audit report?

There is none. No external audit exists. The pilot has a developer's own review and self-run tests with open findings listed honestly.

Not offered / no claim madePermalink

C0487What tests exist?

As of 2026-09-30 the development team's own suites reported 90 of 90 unit tests and three end-to-end suites that passed against the synthetic hub, plus a self-run security probe. They are developer tests, not an audit.

In the pilot (v0.2.0, synthetic data)Permalink

C0488Which security findings remain open?

Among them: a demo signing key kept in the repository, password hashing below the design target, no key rotation, compartments as flags rather than a consent engine, an audit chain that is not write-once, and no per-address rate limit.

In the pilot (v0.2.0, synthetic data)Permalink

C0489Can the pilot hold real patient data?

No. The review says it must not until several findings are fixed, the on-site backend exists, and an independent review is done.

Not offered / no claim madePermalink

C0490Is a penetration test scheduled?

Independent testing is required before any public security claim. Scope and schedule are an open item.

Open decisionPermalink

C0491Is there a security rating?

The design document's self-assessment is a design score, not an audit, and this site does not use it as a marketing headline. Security controls are described instead.

Open decisionPermalink

C0492What documents will IT receive?

Planned deliverables: installation guide, administrator guide, privacy officer guide, security runbooks, interface conformance statements, data dictionary, validation case and end-of-life procedure. They are not written yet.

Designed, not yet builtPermalink

C0493Is there a software bill of materials?

Supply-chain controls such as SBOM, reproducible builds and signed artifacts are designed. An SBOM is not produced today.

Designed, not yet builtPermalink

C0494How will vulnerabilities be patched?

Proposed windows are 72 hours for critical, 14 days for high and 30 days for medium. They are design proposals.

Designed, not yet builtPermalink

C0495Will there be a bug bounty or disclosure process?

A security contact and a disclosure policy file are published on this site. No bounty exists.

Designed, not yet builtPermalink

C0496Is there an incident response plan?

Playbooks for ransomware, insider misuse, credential theft and others are designed with severity levels and notification clocks. Exercises at least twice a year are planned.

Designed, not yet builtPermalink

C0497How are changes to production controlled?

Dual-control, versioned, reversible configuration changes are designed; dual approval for alert policy exists in the pilot.

Designed, not yet builtPermalink

C0498Can IT staff see patient data?

The pilot's IT roles manage users without a path to read charts, and multi-factor is required by default for them.

In the pilot (v0.2.0, synthetic data)Permalink

C0499Can the regulator obtain access logs?

Case-scoped audit extracts to authorized recipients with dual approval are designed. The pilot has audit views.

Designed, not yet builtPermalink

C0500Are hospital certifications tracked?

A reference catalog of a thousand hospital reports, filings and certifications guides design, including 182 Latin American items. The pilot produces none.

Designed, not yet builtPermalink
See the synthetic-data demo first.Request a demo