Security and compliance

Trust posture for supervised clinical AI adoption.

The product should be marketed as designed to support healthcare security workflows. It should not claim HIPAA, DPDP, SOC 2, CDSCO, FDA, or CE certification until those are independently established.

Tenant isolation

Database-level row security is part of the architecture, reducing reliance on application filters alone.

Audit trail

Clinical review actions, report state changes, and access events are built around auditability and retention.

Clinician control

The correct product posture is supervised documentation support, with final clinical responsibility staying with qualified professionals.

Readiness matrix

What can be said today.

These statements keep the marketing site aligned with the current engineering state.

AreaCurrent postureMarketing wording
Regulatory clearanceNot clearedUse "validation-stage clinical decision-support workflow", not cleared medical device language.
Privacy complianceDesigned to supportSay "designed to support HIPAA/DPDP-aligned controls" only when scoped to the implementation.
Enterprise SSOPlannedMarket as roadmap or pilot requirement, not finished capability.
FHIR exportArchitecture presentSay "FHIR-oriented export facade" unless conformance testing is complete.
Clinical validationDesign partner phaseInvite retrospective validation pilots. Do not quote accuracy figures yet.
Important: before a production hospital deployment, remove hardcoded secrets, enforce provider data agreements before PHI leaves the environment, complete SSO, and validate integration behavior with partner systems.