Trust
How we handle data that belongs to patients.
Clinical work carries obligations ordinary enterprise software does not. This is what they are and how we meet them.
Compliance
The regimes we work under
- Canada
- PIPEDA federally, and provincial health privacy legislation including PHIPA in Ontario.
- India
- Digital Personal Data Protection Act 2023.
- Medical devices
- Regulatory status is stated per product and per market during evaluation, under Health Canada, CDSCO, FDA or EU IVDR as applicable.
- Quality management
- ISO 9001:2015 certified.
- Information security
- ISO 27001:2013 certified.
- Certificates
- Copies are provided directly to customers with their scope rather than published for download.
How we handle clinical data
Practice, not policy language.
- Clinical data is de-identified before it enters a training set, and the method is documented for each dataset.
- Training data sits under access control with a record of who used what, and when.
- Deployment can be in-country and fully on-premise where residency requires it.
- Client data is never used to train models for other clients.
- Model versions are pinned per deployment, so a result traces back to the model that produced it.
- Sub-processors are disclosed, and a change of sub-processor is notified rather than silent.
Certificates go to customers under agreement rather than onto a download page. A published certificate can be copied and reattributed, and we have seen it done.
This website
What it collects.
Nothing. No cookies, no analytics, no third-party scripts. Fonts and every other asset are served from the same origin, which is also why there is no consent banner.
If we add analytics later it will be self-hosted and cookieless, and this paragraph will change before it ships.
Security and compliance questionnaires.
Send yours. We answer them ourselves rather than pointing at a portal.