Skip to main content
    Current page: Security
    Security & trust

    Security designed for clinical environments.

    This page describes how PathFree Technologies approaches security, privacy, and clinical safety for AiMediQ™ and datasyteAI™. It is maintained by PathFree Technologies. It is not an independent certification, and does not replace an institution's own security review.

    Trust summary

    Verified facts, honestly labeled.

    Only reviewed and approved items appear here. Where a fact is not yet approved for public disclosure, we render a visible placeholder rather than a claim.

    Regulatory status
    AiMediQ™ powered by datasyteAI™ is currently in the pre-market / development & validation phase.
    Standards referenced
    [WILL BE LISTED HERE]
    Third-party reviews
    [WILL BE LISTED HERE]
    Certifications
    [APPROVED CERTIFICATIONS — none claimed by default]
    Deployment model
    Institutional deployment; specifics confirmed per site
    Data flow

    Where data enters, how it is handled, and what leaves the system.

    A generic view of data flow. Sensitive architecture details are not disclosed publicly; they are shared with institutional partners under appropriate confidentiality.

    1. 1
      Entry

      Approved data enters through institution-scoped inputs during a supported event. No PHI is accepted through public forms on this site.

    2. 2
      Handling

      Data is processed within scoped platform layers with role-based access. Free-text is minimized in favor of structured fields.

    3. 3
      Storage

      Storage location, encryption at rest, retention, and residency are defined per deployment with the institution's privacy and security teams.

    4. 4
      Egress

      Outbound data is limited to defined reporting and integration destinations agreed in the deployment plan. No third-party data sale.

    Generic labels. Component-level architecture is intentionally withheld.

    Controls

    Privacy, encryption, access, audit, resilience, governance, deployment, and response.

    Each control is described in institutional language with an explicit shared-responsibility indicator. Nothing here should be read as a certification.

    Privacy

    In Progress

    Purpose-limited processing, data minimization, and role-based visibility. Privacy notices and lawful basis are defined per deployment.

    Ownership: Shared

    Encryption

    Current

    Transport encryption using current industry-standard TLS. Encryption at rest and key-management specifics are confirmed per deployment.

    Ownership: Platform

    Access control

    In Progress

    Role-based access with least-privilege defaults. Integration with the institution's identity provider is planned per deployment.

    Ownership: Shared

    Auditability

    Current

    Time-stamped event capture and configuration versioning support internal review, QA, and — where applicable — regulatory conformance work.

    Ownership: Platform

    Resilience

    In Progress

    Availability, backup, and recovery objectives are defined per deployment with institutional stakeholders. Specifics are shared under confidentiality.

    Ownership: Shared

    Model governance

    Current

    Models, prompts, and protocol configurations are versioned and change-controlled. Clinician-in-the-loop is enforced by design.

    Ownership: Platform

    Deployment options

    In Progress

    Deployment model is institutional; specific hosting, tenancy, and residency options are confirmed with the institution during discovery.

    Ownership: Shared

    Incident response

    Current

    Defined internal procedures cover triage, communication, and remediation. Institution-specific escalation paths are agreed as part of deployment.

    Ownership: Shared
    Capability matrix

    Current, in progress, and planned — never mixed.

    Roadmap items are labeled to prevent them from being mistaken for present capabilities.

    AreaStateNotes
    Structured event captureCurrentTime-stamped, versioned event capture within the platform.
    Role-based access controlsCurrentLeast-privilege defaults with role scoping.
    Institutional identity integrationIn ProgressAlignment with institution identity providers during deployment discovery.
    Formal third-party security reviewPlannedExternal review will be scoped and disclosed once contracted and completed.
    Certification programsPlanned[APPROVED CERTIFICATIONS ROADMAP] — nothing claimed by default.
    Post-quantum cryptographyPlannedUnder evaluation. Specific algorithms, scope, standard status, and verification evidence will be disclosed only when approved.
    Post-quantum cryptography

    Under evaluation, not yet claimed.

    We take future cryptographic threats seriously. We do not, however, make post-quantum claims that are not backed by documented algorithms, implementation scope, standard status, and verification evidence.

    What we will publish here — and what we will not
    When PathFree adopts a specific post-quantum algorithm, we will state: the algorithm name and parameter set, the standard it corresponds to and its standard status, the exact scope of implementation (which surfaces and data flows), and the verification evidence supporting the claim. Generic references to “NIST-certified” cryptography will not be used.
    Security contact and responsible disclosure

    How to reach the security team.

    Security contact

    For security questions, coordinated disclosure, or the Security Brief request, email the security team directly.

    info@pathfree.com

    Responsible disclosure

    We welcome coordinated disclosure of suspected vulnerabilities. Please:

    • Report only through the security email above.
    • Do not include patient information or protected health information.
    • Give us reasonable time to investigate before public disclosure.
    • Avoid actions that could disrupt services or affect other users.

    Security & trust — FAQ

    Find answers to common questions about our technology and services

    Institutional buyers

    Request the Security Brief.

    The Security Brief covers current controls, deployment options, data handling, and roadmap details under appropriate confidentiality.