Trust Center
Security: what we built, what we found, what we have not done
We describe controls, not ratings. Every finding from our own review that is still open is listed below.
Controls in the pilot
Tested by the developer on synthetic data. Not independently reviewed.
| Area | What exists | Status |
|---|---|---|
| Access | Deny-by-default roles, care-relationship scoping, tenant isolation tests; cross-tenant access refused in every test. | In the pilot (v0.2.0, synthetic data) |
| Sign-in | Long passwords (12, or 14 in the Hospital preset), forced first change, TOTP MFA with recovery codes (on by default for privileged tiers), lockout after 5 failures with alert, generic errors, idle lock, session list and revoke. | In the pilot (v0.2.0, synthetic data) |
| Privileged changes | Two-person approval for privileged user changes and for alert policy and code edits. | In the pilot (v0.2.0, synthetic data) |
| Audit | Per-clinic SHA-256 hash chain with a verify button. Edit, delete, reorder, truncate and forged-head tests are detected. | In the pilot (v0.2.0, synthetic data) |
| Emergency access | Break-glass with reason, time limit, alert to privacy staff and mandatory review. | In the pilot (v0.2.0, synthetic data) |
| Data protection | HTTPS and WSS; field-level AES-GCM encryption of national IDs, MFA secrets and change history. | In the pilot (v0.2.0, synthetic data) |
| Application | CSP and security headers, CORS allow-list, parameterised SQL, no raw-markup APIs in the client, sandboxed desktop app with three IPC channels. | In the pilot (v0.2.0, synthetic data) |
| Configuration | Signed manifests, locked safety floors enforced again at run time, tamper detection on packages. | In the pilot (v0.2.0, synthetic data) |
How to read status labels: In the pilot (v0.2.0, synthetic data) Simulated in the pilot Coming (Wave 2, rolling out) Designed, not yet built Open decision Not offered / no claim made Planned partner integration
Open findings from our own review
Reviewed by the developer, September 2026. Published in full.
| Finding | Status |
|---|---|
| Demo signing private key is in the demo code base; production key custody undecided. | Open decision |
| Passwords use PBKDF2-SHA256 (100,000 iterations), not Argon2id; no breached-password check. | Open decision |
| Field-encryption key has no rotation, no per-tenant keys, no key management service. | Open decision |
| Compartments are flags plus an attested purpose, not a legal consent engine. | Open decision |
| Audit chain is not write-once and has no external anchor. | Open decision |
| No per-IP rate limit. | Open decision |
| Break-glass lookup reveals that a restricted record exists (audited, role-limited). | Accepted for the pilot |
| Bearer tokens are kept in session storage. | Accepted for the pilot |
Residual risk, in our own words
The pilot is safe to demonstrate with synthetic data. It must not hold real patient data until the findings above are addressed and an independent review has been done.
Designed, not built
These would matter to a hospital. None of them exists yet.
On-site closed servers Designed
Patient data held in the clinic, with sync paused rather than data exposed.
Federated ledger Designed
Hashes, consent records and audit events only. Patient records never go on the ledger.
Read-side limiter Designed
Unusual bulk reads pause sync while local care continues. Thresholds are open.
Hybrid post-quantum key exchange Designed
Design target for server-to-server transfer. Not implemented and not independently evaluated.
Sealed terminals and analog layer Designed
Untested hardware ideas. The goal is data that is hard to harvest. We do not claim it can never be breached.
Independent review Open
Scope, provider and timing are undecided. No penetration test has been done.
What we do not claim
- No certification, attestation or compliance with HIPAA, ONC, SOC 2, ISO 27001, HITRUST, GDPR, LGPD or FDA rules.
- No security rating, audit result or penetration test.
- No uptime, latency or throughput figures.
- No claim that any system is unbreakable.
Reporting a vulnerability: see security.txt.
Questions
Are you certified or audited?
Where do you report a vulnerability?
Is data encrypted?
Ask your hardest security question
Search the help center, or send it to us.