Trust

How we handle data that belongs to patients.

Clinical work carries obligations ordinary enterprise software does not. This is what they are and how we meet them.

Compliance

The regimes we work under

Canada
PIPEDA federally, and provincial health privacy legislation including PHIPA in Ontario.
India
Digital Personal Data Protection Act 2023.
Medical devices
Regulatory status is stated per product and per market during evaluation, under Health Canada, CDSCO, FDA or EU IVDR as applicable.
Quality management
ISO 9001:2015 certified.
Information security
ISO 27001:2013 certified.
Certificates
Copies are provided directly to customers with their scope rather than published for download.

How we handle clinical data

Practice, not policy language.

  • Clinical data is de-identified before it enters a training set, and the method is documented for each dataset.
  • Training data sits under access control with a record of who used what, and when.
  • Deployment can be in-country and fully on-premise where residency requires it.
  • Client data is never used to train models for other clients.
  • Model versions are pinned per deployment, so a result traces back to the model that produced it.
  • Sub-processors are disclosed, and a change of sub-processor is notified rather than silent.
Certificates go to customers under agreement rather than onto a download page. A published certificate can be copied and reattributed, and we have seen it done.

This website

What it collects.

Nothing. No cookies, no analytics, no third-party scripts. Fonts and every other asset are served from the same origin, which is also why there is no consent banner.

If we add analytics later it will be self-hosted and cookieless, and this paragraph will change before it ships.

Security and compliance questionnaires.

Send yours. We answer them ourselves rather than pointing at a portal.