Tenant isolation
Database-level row security is part of the architecture, reducing reliance on application filters alone.
The product should be marketed as designed to support healthcare security workflows. It should not claim HIPAA, DPDP, SOC 2, CDSCO, FDA, or CE certification until those are independently established.
Database-level row security is part of the architecture, reducing reliance on application filters alone.
Clinical review actions, report state changes, and access events are built around auditability and retention.
The correct product posture is supervised documentation support, with final clinical responsibility staying with qualified professionals.
These statements keep the marketing site aligned with the current engineering state.
| Area | Current posture | Marketing wording |
|---|---|---|
| Regulatory clearance | Not cleared | Use "validation-stage clinical decision-support workflow", not cleared medical device language. |
| Privacy compliance | Designed to support | Say "designed to support HIPAA/DPDP-aligned controls" only when scoped to the implementation. |
| Enterprise SSO | Planned | Market as roadmap or pilot requirement, not finished capability. |
| FHIR export | Architecture present | Say "FHIR-oriented export facade" unless conformance testing is complete. |
| Clinical validation | Design partner phase | Invite retrospective validation pilots. Do not quote accuracy figures yet. |