Transparency
What's built today
Every capability, its status and its limits. Version 0.2.0, verified September 30, 2026. The pilot runs on synthetic data only.
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
Communication and alerts
| Capability | Status | Limits |
|---|---|---|
| Live chart push | In the pilot (v0.2.0, synthetic data) | Alerts and pushes reach connected clients only. |
| Facility messaging | In the pilot (v0.2.0, synthetic data) | Cloud required; not end-to-end encrypted. |
| Memo Desk | In the pilot (v0.2.0, synthetic data) | No drafts, due-date escalation or retention purge. |
| Codes and alerts (22 default templates) | In the pilot (v0.2.0, synthetic data) | No pager, SMS or overhead paging. Timers are example values. |
| Two-person cancel of imminent-threat alerts | In the pilot (v0.2.0, synthetic data) | Who counts as the two people is an open decision. |
| Critical result alerts | Simulated in the pilot | Results enter through an internal interface. |
Patient record
| Capability | Status | Limits |
|---|---|---|
| Registration and duplicate warning | In the pilot (v0.2.0, synthetic data) | No national-ID validators, no barcode printing, matching untuned on real data. |
| Two-person merge and unmerge | In the pilot (v0.2.0, synthetic data) | Virtual merge; no ADT or FHIR messages emitted. |
| Coded problems, allergies, medications, immunizations | In the pilot (v0.2.0, synthetic data) | Bundled code sets are subsets; no interaction checking. |
| Vitals, free-text notes, free-text orders | In the pilot (v0.2.0, synthetic data) | Basic only. Not clinical documentation. |
| Audit chain and verify button | In the pilot (v0.2.0, synthetic data) | Tamper-evident, not write-once storage. |
| VIP and break-glass | In the pilot (v0.2.0, synthetic data) | Compartments are flags plus an attested purpose, not a consent engine. |
| Notes with signing, CPOE, forms, permission matrix | Coming (Wave 2, rolling out) | Wave 2 (v0.3.0) is rolling out and not yet verified. |
| Lab and imaging simulators | Coming (Wave 2, rolling out) | Wave 2. Today only a basic internal result interface exists. |
| Scheduling, billing, portal, pharmacy, e-prescribing | Designed, not yet built | Not started. |
Platform and security
| Capability | Status | Limits |
|---|---|---|
| Multi-tenant hub (four synthetic tenants) | In the pilot (v0.2.0, synthetic data) | One shared cloud hub. Dedicated deployment per customer is planned. |
| AuroraMed Packaging (13-module catalog, two presets, signed packages) | In the pilot (v0.2.0, synthetic data) | Demo signing key; no rollback UI or staged rollout. |
| MFA (TOTP), lockout, idle lock, two-person privileged changes | In the pilot (v0.2.0, synthetic data) | Passwords use PBKDF2, not Argon2id. No FIDO2 or single sign-on. |
| Field encryption of national IDs and MFA secrets | In the pilot (v0.2.0, synthetic data) | No key rotation, no per-tenant keys yet. |
| On-site closed server, federated ledger, read limiter, sealed terminals, analog timing layer | Designed, not yet built | Designed, not built. Effectiveness of screens and hardware is untested. |
| Working with the network down | Designed, not yet built | Not met by the pilot; a network outage stops alerts and messaging. |
| HL7, FHIR, DICOM, e-prescribing, clearinghouse, SMS or pager | Designed, not yet built | None built. FHIR is planned. |
| Spanish or Portuguese product screens | Not offered / no claim made | English only. Spanish website pages are marketing previews. |
Checks we ran, and what they are
As of September 30, 2026, on synthetic data, run by the developer: 90 of 90 unit checks pass; end-to-end suites of 108, 201 and 51 checks pass locally and on the live hub; a 37-step interface click-through passed; a scan of 122 screens found no problems; and the developer's own 34-check security probe passed after two real problems it found were fixed. These are internal tests. They are not an audit, not a penetration test, and not proof for real patient data.
Open security findings (published, not hidden)
- The demo signing private key is in the demo code base; production key custody is undecided.
- Passwords use PBKDF2-SHA256, not Argon2id, and there is no breached-password check.
- The field-encryption key has no rotation and no per-tenant keys.
- Privacy compartments are flags, not a legal consent engine.
- The audit chain is not write-once and has no external anchor.
- There is no per-IP rate limit.
Our own review states the pilot must not hold real patient data until these are addressed and an independent review has been done.
Questions about a specific item?
Search all 1,000 answered concerns, or ask us.