Data minimisation
Collect only what the task needs, so the medical context stays focused and the exposure stays small.
How we intend to protect medical information, and what we are not claiming today.
Read this first
This page describes how we are designing Astraon AI. It is not an audit result, a certification or a compliance claim.
Treat everything here as a statement of intent. If you need specifics for a security review, ask us and we will answer plainly.
Ask us for detailThey shape every decision about how medical information is handled.
Collect only what the task needs, so the medical context stays focused and the exposure stays small.
Layered permissions, so only authorised users can reach sensitive information.
Our aim is to protect data in transit and at rest with current, well-established cryptography.
Access and changes are designed to be recorded, so it is possible to verify who did what, and when.
We know which frameworks govern medical data. Awareness is where we are; certification is not.
We are designing with the principles of the Digital Personal Data Protection Act in mind.
Awareness · not certifiedThe architecture is informed by HIPAA principles. That is not a compliance certification.
Awareness · not certifiedWhat we ask of you
Forms on this site are public and are not secure channels. If an evaluation needs sensitive information, we will agree a secure channel after first contact.
Ask about security, privacy and data handling. We will answer plainly.