Trust architecture
Service security
Controlled demonstration
This description presents currently visible technical controls. It is neither a certification nor a regulatory compliance attestation.
Implemented controls
- central console separated from the public site and protected by access controls;
- explicit authorized-address list and upstream strong authentication;
- service enrollment with cryptographic proof, certificates, and one-time activation;
- two-person approval planned for sensitive production admissions;
- data minimization, opaque routes, and neutral notification content;
- notifications only after an explicit action by hospital staff;
- chained audit log and administrative revocation;
- browser protection headers and HTTPS encryption on the public domain.
Hospital model
The hospital server must remain protected and initiate outbound communications to its authorized relay. A patient link is optional, temporary, and must be closed when care begins or the encounter ends.
Conditions before production
A formal risk analysis, privacy impact assessment, independent penetration testing, incident and breach response plan, retention policy, agreements with providers and hospitals, and legal validation for each jurisdiction remain mandatory. Keys, certificates, backups, and logs must also be managed through approved production services.
Vulnerability reporting
The official security reporting channel will be published before the service opens. Until then, no personal data, exploitation evidence, or clinical information should be sent through the public site.