Ledger, sync, offline and hardware requirements
On-site server, sealed terminals, hardware profile
Physical system.
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
C0958What does the on-site server look like for a small hospital versus a large one?
No. The specification describes it, but the pilot does not include it. For reference, REQ-3301 (a top-priority requirement, all three tiers) says one closed-loop server per small hospital in a single cabinet; larger sites use multi-node clusters. Check: cabinet build passes inventory and burn-in.
C0959What are the sealed terminals meant to be?
Terminals must be sealed, input-only thin clients that store nothing and show a live feed, with waterproof rubber case, hinged waterproof keyboard, cooling fins and sleeved USB. That is REQ-3302, a top-priority requirement for all three tiers. Not yet. It is designed in the specification and not built in the pilot. Test in the specification: power-cycle test: no PHI remains; ingress test to the IP rating [Open, design proposes IP66+]. Parts of it are explicitly marked as open in the specification.
C0960Are USB ports on the terminals open?
Designed, not built: there is no code for this in the pilot. REQ-3303 says Terminal USB must be electrically gated: allow-listed VID/PID, HID/CCID classes only, disabled in strict tier. Its acceptance check: unknown device does not enumerate.
C0961Do the camera-resistant screens work?
REQ-3304 is a high-priority requirement for all three tiers: camera-resistant screens must use side-angle privacy filtering and the refresh-pattern measure; effectiveness against real cameras is untested and must not be claimed until measured. This is on the design side of the line. Nothing in v0.2.0 does it. To verify it, the specification says no marketing claim exists without lab data; measurement plan exists.
C0962How would a terminal prove it has not been tampered with?
The on-site server, sealed terminals, hardware profile part of the specification (REQ-3305) says terminals must attest to the server at boot and per session (TPM/secure element) and refuse to render on mismatch. No. The specification describes it, but the pilot does not include it. Acceptance check: tampered image fails attestation and gets quarantined.
C0963What happens if someone opens a terminal?
How would it be tested? The specification says open-case test triggers alert. That is the check for REQ-3306: tamper switches must zeroize keys and alert. Not yet. It is designed in the specification and not built in the pilot.
C0964Does AuroraMed track the equipment it sells?
Designed, not built: there is no code for this in the pilot. For reference, REQ-3307 (a high-priority requirement, all three tiers) says equipment sold by AuroraMed must be tracked as assets with serial, warranty and installed location. Check: asset register lists every terminal.