AuroraMed v0.2.0 is a synthetic-data pilot. See exactly what's built →

Security controls

Network, hardware and physical security

The closed-loop site, sealed terminals and physical controls.

How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration

C0160What does a closed-loop server mean for hackers?

No inbound path from the internet, segmented zones, controlled egress and 802.1X on terminal ports. It reduces exposure but is not a guarantee.

Designed, not yet builtPermalink

C0161What is a sealed thin-client terminal?

A rubber-cased, input-only terminal that stores nothing and shows a live feed from the server. A power-cycled terminal should contain no patient data. Hardware is designed, not built.

Designed, not yet builtPermalink

C0162Can a lost tablet leak patient data?

By design no patient data sits on mobile devices: the tablet renders a server feed and stores nothing locally.

Designed, not yet builtPermalink

C0163Do the screens stop someone photographing them?

A privacy filter narrows viewing angles. The refresh pattern meant to clash with cameras is untested and no effectiveness is claimed. Watermarking and attribution are the stronger deterrent.

Designed, not yet builtPermalink

C0164Are USB ports a risk?

Terminals use allow-listed peripherals and sleeved ports, and the strict tier can disable USB entirely.

Designed, not yet builtPermalink

C0165What if someone opens a terminal?

Tamper switches are designed to wipe keys. Physical attacks by insiders remain an acknowledged risk.

Designed, not yet builtPermalink

C0166Are servers physically protected?

A lockable cabinet with tamper labels, intrusion switches, door sensor and camera logging is the reference profile. Insiders with keys at small clinics remain a known gap.

Designed, not yet builtPermalink

C0167How does the server resist malware?

Minimal hardened OS, secure boot, disk encryption, allow-listing of software and signed, immutable update images are designed.

Designed, not yet builtPermalink

C0168Is there network segmentation?

Nine zones with deny-by-default flow rules are designed, separating egress, management, application, data, ledger, terminals and guests.

Designed, not yet builtPermalink

C0169Can guests use clinic Wi-Fi to reach clinical systems?

No. There is no guest or personal-device access to clinical services in the design; tablets join through certificate-based enterprise Wi-Fi.

Designed, not yet builtPermalink

C0170What about the printer as a leak path?

Printers are wired and non-networked with no email-to-print or mobile printing, and jobs are logged and watermarked. Watermark format and rate limits are open.

Designed, not yet builtPermalink

C0171What is the analog timing layer?

An optional physical-proximity factor inside one shielded room for high-risk actions. The hardware is untested, it is the least mature part of the design, and it is never the only lock. The goal is unharvestable, not unhackable.

Designed, not yet builtPermalink

C0172Is the analog layer required?

No. It is optional and its construction, timing values and tolerances are open. Routine care never depends on it.

Designed, not yet builtPermalink

C0173Do shielded rooms stop insiders?

No. They stop remote relay and some emission attacks. Insider controls are separate.

Designed, not yet builtPermalink
See the synthetic-data demo first.Request a demo