AuroraMed v0.2.0 is a synthetic-data pilot. See exactly what's built →

Trust Center

Security: what we built, what we found, what we have not done

We describe controls, not ratings. Every finding from our own review that is still open is listed below.

Controls in the pilot

Tested by the developer on synthetic data. Not independently reviewed.

AreaWhat existsStatus
AccessDeny-by-default roles, care-relationship scoping, tenant isolation tests; cross-tenant access refused in every test.In the pilot (v0.2.0, synthetic data)
Sign-inLong passwords (12, or 14 in the Hospital preset), forced first change, TOTP MFA with recovery codes (on by default for privileged tiers), lockout after 5 failures with alert, generic errors, idle lock, session list and revoke.In the pilot (v0.2.0, synthetic data)
Privileged changesTwo-person approval for privileged user changes and for alert policy and code edits.In the pilot (v0.2.0, synthetic data)
AuditPer-clinic SHA-256 hash chain with a verify button. Edit, delete, reorder, truncate and forged-head tests are detected.In the pilot (v0.2.0, synthetic data)
Emergency accessBreak-glass with reason, time limit, alert to privacy staff and mandatory review.In the pilot (v0.2.0, synthetic data)
Data protectionHTTPS and WSS; field-level AES-GCM encryption of national IDs, MFA secrets and change history.In the pilot (v0.2.0, synthetic data)
ApplicationCSP and security headers, CORS allow-list, parameterised SQL, no raw-markup APIs in the client, sandboxed desktop app with three IPC channels.In the pilot (v0.2.0, synthetic data)
ConfigurationSigned manifests, locked safety floors enforced again at run time, tamper detection on packages.In the pilot (v0.2.0, synthetic data)

How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration

Open findings from our own review

Reviewed by the developer, September 2026. Published in full.

FindingStatus
Demo signing private key is in the demo code base; production key custody undecided.Open decision
Passwords use PBKDF2-SHA256 (100,000 iterations), not Argon2id; no breached-password check.Open decision
Field-encryption key has no rotation, no per-tenant keys, no key management service.Open decision
Compartments are flags plus an attested purpose, not a legal consent engine.Open decision
Audit chain is not write-once and has no external anchor.Open decision
No per-IP rate limit.Open decision
Break-glass lookup reveals that a restricted record exists (audited, role-limited).Accepted for the pilot
Bearer tokens are kept in session storage.Accepted for the pilot

Residual risk, in our own words

The pilot is safe to demonstrate with synthetic data. It must not hold real patient data until the findings above are addressed and an independent review has been done.

Designed, not built

These would matter to a hospital. None of them exists yet.

On-site closed servers Designed

Patient data held in the clinic, with sync paused rather than data exposed.

Federated ledger Designed

Hashes, consent records and audit events only. Patient records never go on the ledger.

Read-side limiter Designed

Unusual bulk reads pause sync while local care continues. Thresholds are open.

Hybrid post-quantum key exchange Designed

Design target for server-to-server transfer. Not implemented and not independently evaluated.

Sealed terminals and analog layer Designed

Untested hardware ideas. The goal is data that is hard to harvest. We do not claim it can never be breached.

Independent review Open

Scope, provider and timing are undecided. No penetration test has been done.

What we do not claim

  • No certification, attestation or compliance with HIPAA, ONC, SOC 2, ISO 27001, HITRUST, GDPR, LGPD or FDA rules.
  • No security rating, audit result or penetration test.
  • No uptime, latency or throughput figures.
  • No claim that any system is unbreakable.

Reporting a vulnerability: see security.txt.

Questions

Are you certified or audited?
No. There is no certification, attestation, external audit or penetration test. Our own review is a developer self-review, and it says the pilot must not hold real patient data.
Where do you report a vulnerability?
Email [email protected]. See security.txt. We do not run a bounty programme, and the pilot holds only synthetic data.
Is data encrypted?
Connections use HTTPS and secure WebSockets. National IDs, MFA secrets and registration change history are encrypted in the database. Other fields, including messages, are stored in plaintext in the database. Key rotation and per-tenant keys are not built.

Ask your hardest security question

Search the help center, or send it to us.

See the synthetic-data demo first.Request a demo