Security designed for clinical environments.
This page describes how PathFree Technologies approaches security, privacy, and clinical safety for AiMediQ™ and datasyteAI™. It is maintained by PathFree Technologies. It is not an independent certification, and does not replace an institution's own security review.
Verified facts, honestly labeled.
Only reviewed and approved items appear here. Where a fact is not yet approved for public disclosure, we render a visible placeholder rather than a claim.
Where data enters, how it is handled, and what leaves the system.
A generic view of data flow. Sensitive architecture details are not disclosed publicly; they are shared with institutional partners under appropriate confidentiality.
- 1Entry
Approved data enters through institution-scoped inputs during a supported event. No PHI is accepted through public forms on this site.
- 2Handling
Data is processed within scoped platform layers with role-based access. Free-text is minimized in favor of structured fields.
- 3Storage
Storage location, encryption at rest, retention, and residency are defined per deployment with the institution's privacy and security teams.
- 4Egress
Outbound data is limited to defined reporting and integration destinations agreed in the deployment plan. No third-party data sale.
Generic labels. Component-level architecture is intentionally withheld.
Privacy, encryption, access, audit, resilience, governance, deployment, and response.
Each control is described in institutional language with an explicit shared-responsibility indicator. Nothing here should be read as a certification.
Privacy
In ProgressPurpose-limited processing, data minimization, and role-based visibility. Privacy notices and lawful basis are defined per deployment.
Encryption
CurrentTransport encryption using current industry-standard TLS. Encryption at rest and key-management specifics are confirmed per deployment.
Access control
In ProgressRole-based access with least-privilege defaults. Integration with the institution's identity provider is planned per deployment.
Auditability
CurrentTime-stamped event capture and configuration versioning support internal review, QA, and — where applicable — regulatory conformance work.
Resilience
In ProgressAvailability, backup, and recovery objectives are defined per deployment with institutional stakeholders. Specifics are shared under confidentiality.
Model governance
CurrentModels, prompts, and protocol configurations are versioned and change-controlled. Clinician-in-the-loop is enforced by design.
Deployment options
In ProgressDeployment model is institutional; specific hosting, tenancy, and residency options are confirmed with the institution during discovery.
Incident response
CurrentDefined internal procedures cover triage, communication, and remediation. Institution-specific escalation paths are agreed as part of deployment.
Current, in progress, and planned — never mixed.
Roadmap items are labeled to prevent them from being mistaken for present capabilities.
| Area | State | Notes |
|---|---|---|
| Structured event capture | Current | Time-stamped, versioned event capture within the platform. |
| Role-based access controls | Current | Least-privilege defaults with role scoping. |
| Institutional identity integration | In Progress | Alignment with institution identity providers during deployment discovery. |
| Formal third-party security review | Planned | External review will be scoped and disclosed once contracted and completed. |
| Certification programs | Planned | [APPROVED CERTIFICATIONS ROADMAP] — nothing claimed by default. |
| Post-quantum cryptography | Planned | Under evaluation. Specific algorithms, scope, standard status, and verification evidence will be disclosed only when approved. |
Under evaluation, not yet claimed.
We take future cryptographic threats seriously. We do not, however, make post-quantum claims that are not backed by documented algorithms, implementation scope, standard status, and verification evidence.
How to reach the security team.
Security contact
For security questions, coordinated disclosure, or the Security Brief request, email the security team directly.
info@pathfree.comResponsible disclosure
We welcome coordinated disclosure of suspected vulnerabilities. Please:
- Report only through the security email above.
- Do not include patient information or protected health information.
- Give us reasonable time to investigate before public disclosure.
- Avoid actions that could disrupt services or affect other users.
Security & trust — FAQ
Find answers to common questions about our technology and services
Request the Security Brief.
The Security Brief covers current controls, deployment options, data handling, and roadmap details under appropriate confidentiality.