Security & Trust
Built to be trusted with healthcare data
Trust is shown, not assumed. Here is how we protect your data across the Cortex platform and the products it powers.
Never trained on your data
Your documents and records are used only to answer your questions — never to train a model, ours or a provider’s.
Access-scoped in the database
Organization → branch → department scoping is enforced in Postgres views, deny-by-default. An unset context returns zero rows, never all rows.
Field-level PHI encryption
Protected health information is encrypted at the field level, with HMAC blind indexes so it stays searchable without exposing plaintext.
Tamper-evident audit
A hash-chained audit log where each entry seals the previous — so the record of who did what cannot be quietly altered.
Read-only SQL guardrails
Model-written SQL is confined to a read-only, single-statement transaction over approved views, with hard row caps and a deterministic fallback.
Provenance on every answer
Answers carry the source passage, the query that ran, and the rows scanned — so you can verify, not just trust.
Fail-closed authorization
Authorization decisions default to denied; access is granted explicitly, not assumed.
Human-in-the-loop
AI proposes; a person disposes. AI-drafted content becomes a record only when a human approves it.
Deployment & hosting
- Delivered on Microsoft Azure — for custom builds, we can deliver inside your own Azure subscription and identity tenant, so PHI need never leave your tenancy.
- Data-residency options for export markets, decided up front.
- A Business Associate Agreement (BAA) can be executed before access to PHI.
Engineered to support — stated plainly
Our systems are engineered to support HIPAA, HL7/FHIR R4, ISO 13485, ISO 14971, and 21 CFR Part 11, and we document how the architecture meets them.
We do not currently hold SOC 2 Type II, HITRUST, or ISO 27001 attestations, and we say so plainly rather than imply otherwise. Determining which regime applies to your product, and certifying that it is met, is work for qualified counsel; nothing here is legal advice.
Questions from your security team?
We’re happy to walk through architecture, controls, and deployment options in detail.
Talk to us