Security questions
This page summarizes the beta posture. Technical and operational scope must be confirmed for each deployment.
Does the system send PHI to external services?
Third-party PHI sharing is disabled by default. Explicitly public queries without PHI indicators may reach approved external providers. Canonical clinical research should use redacted queries before calling external sources.
See Privacy and trust for limits and exceptions.
Does the system make clinical decisions?
No. The product prepares drafts, organizes context, and retrieves evidence. The professional reviews each output and retains the final decision.
Does every output pass through the same verification?
No. The canonical task pipeline has evidence, context, and provenance rails. Clipboard, Plan, Academy, and helper actions have their own contracts. The interface must show the traceability that is actually available for each path.
Is every action covered by an audit trail?
We do not assume universal coverage. The backend records events, usage, and decisions across several paths, but scope varies by service. Deployment review must confirm which actions, failures, and accesses are persisted.
Is the product HIPAA or LGPD certified?
We do not claim formal certification. The architecture includes controls relevant to a compliance posture, but compliance also depends on operations, contracts, policies, training, and legal assessment.
Can I use my own providers?
A BYOK registry exists for configured environments. Commercial availability, supported providers, and sharing rules must be confirmed before use.
How should an institution evaluate the system?
Start with a bounded workflow. Review permitted data, external paths, roles, retention, logs, clinical criteria, and incident response before including real patients.