Trust & security

What's true, what's in progress, and what we deliberately don't claim.

Clinical monitoring software earns trust the way monitors do: by showing its work and never overstating. This page is our standing answer to security reviews. Three lists, dated, kept current. If a claim you need is missing, ask. We'd rather say “not yet” than imply.

Last reviewed: 2026-08-16

Column A

True today — mechanisms, not adjectives.

Each claim names the mechanism that enforces it. Re-verified against the product whenever this page changes.

Human sign-off on every artifact

Every AI-drafted report and letter requires a named reviewer to edit and approve before it exists as a finished document. There is no autonomous path to a signed artifact.

Signature manifestation and tamper-evident binding

Every signed report and sent letter displays the signer's printed name, the full UTC time of signing, and the meaning of the signature — frozen at sign time. A database-derived SHA-256 digest binds that content to the signer and timestamp and is re-verified on every render, so a post-signature alteration surfaces as a mismatch instead of passing silently. This is tamper-evidence, not a cryptographic signature (Column C). The printed name is the name on the account; we do not yet record an identity verification before first signature, and we do not claim a verified printed name under 21 CFR 11.50.

Append-only audit trail, written by the database

Audit rows are produced by database triggers inside the same transaction as the change they record — an action whose audit write fails does not happen. Each row carries before-and-after values and the actor's identity and authority; application users have no direct write path to the trail, and the database permits no updates or deletes to it.

Per-artifact source provenance

Every source data point carries its provenance class (certified copy, central-lab feed, EMR feed, or pending), and an attestation, once made, is frozen by a database trigger. Corrections create new versions; nothing is silently rewritten.

Tenant isolation enforced in the database

Row-level security scopes source data by site and clinical work by assignment, verified with real authenticated sessions (not admin backdoors) as part of our release process.

Role-based authority, enforced in the database

Who may sign a report, send a letter, or adjudicate a data-mapping decision is a distinct, database-checked permission — not a UI affordance — and the authority in force is snapshotted onto the regulated record at the moment of the action.

The AI shows its inputs

Reviewers see the structured data sent to the model beside every draft; drafts mark uncertainty explicitly ([VERIFY: …]) rather than papering over it.

No PHI in our demo environments

All demonstration data is synthetic by policy; subject codes, documents, and lab values are fabricated. A live study with real patient data starts only under a BAA with you.

Encryption in transit and at rest

TLS everywhere; database and document storage encrypted at rest (AES-256).

Read-only toward your systems of record

We never write to your EDC or a site's EHR. Queries are drafted here, raised by your CRA in your EDC.

Business Associate Agreements across the subprocessor chain

BAAs are signed with the subprocessors that could handle protected health information — hosting, database, and AI providers. We will name the chain and each agreement's scope on request under NDA.

Column B

In progress — dated when the letters are signed.

We publish target dates the day an engagement letter is signed, not before. A hoped-for date is worse than none.

SOC 2 Type IIn progress

Auditor selection under way; the engagement date and report target publish here the day the letter is signed. Type II observation window follows immediately.

Unlocks: Shortens security questionnaires to one link.

Independent penetration testIn progress

Scheduled as part of the SOC 2 program; letter available under NDA thereafter.

Unlocks: Third-party validation of the isolation claims above.

Enterprise SSOIn progress

SAML/OIDC single sign-on against your existing identity provider (Okta, Entra, or equivalent). This is our build, not a configuration step on your side; we date it here when the work is scheduled.

Unlocks: Lets your team sign in with the identity provider they already use.

Generation recordsIn progress

Every AI output stored with its exact prompt, model version, and input snapshot, so “why did the AI write this?” is answerable for any historical draft. Our AI-governance page publishes alongside this.

Unlocks: Model-change-control evidence for sponsor audits.

Column C

Deliberately not claimed.

The credibility column. If a vendor claims these loosely, these make good diligence questions.

We do not claim 21 CFR Part 11 electronic signatures

In-product approvals are named review attestations. The record you sign lives in your existing validated system (eTMF/QMS); we export the evidence of the human review — the signed report and its audit trail. If and when customers want in-system signatures of record, that becomes a scoped, validated program, announced here first.

We do not claim the AI makes monitoring decisions

Deterministic software computes matches and discrepancies; the model drafts prose around computed results; your monitor decides. We consider “the AI found a deviation” a category error and design so it can't be true.

We do not claim cryptographic signatures

Typed-name attestations are exactly that, attributed to an authenticated account in the audit trail. The content-binding digest in Column A is keyless tamper-evidence, not PKI signing — we name the difference rather than blur it.

We do not claim “HIPAA certified”

No such certification exists. We claim specific safeguards and signed BAAs (both above), and will show you the mapping.

We do not claim autonomous EDC or EHR writes — and never will

Read-only is enforced at the credential level, not by policy alone.

Get in touch

See it on your monitoring workload.

CRO, sponsor, quality, or still evaluating — tell us what you're looking at. We'll show you the product on synthetic data. If a pilot is the right next step, we'll scope it on one study.

We use this only to reply. No cookies, no tracking — what we keep and for how long.

Synthetic demo data — no PHI on this site·Typed-name attestations, not cryptographic signatures·Append-only audit trail·Read-only toward your EDC and EHR