Skip to content
Private early access Join the waitlist
Medical Core

Language

Log in

Trust Center

Security, privacy and responsible AI, explained clearly.

Medical Core is designed for healthcare teams that need patient data, clinical decisions and staff actions to remain traceable. This page explains the main controls clinics can review before they start.

Clinician
approval boundary
Audit
review and export trail
Consent
patient app submissions
2FA
CMS security control

We describe only the controls and capabilities we can support. Formal requirements, contracts and deployment responsibilities are confirmed with each clinic before launch.

Control map

Controls to review before launch.

Identity and access

Role-based access, team scoping, optional 2FA enforcement, login audit trails and admin recovery controls.

Patient app consent

Invite links, consent records, submitted data and clinician review status stay connected to the patient record.

Data protection

Data is encrypted in transit, secrets are encrypted, backups are checked and exports are controlled.

Activity history

App submissions, reviews, follow-ups, tasks, appointments and exports keep a clear history.

Responsible AI boundaries

AI can summarize, draft and highlight. Clinicians approve care decisions, diagnosis and treatment changes.

Incident response

Response procedures, security checks and escalation contacts are maintained for operational and security incidents.

Responsible AI

AI supports doctors. It does not replace them.

Medical Core can summarize information, highlight configured risks and draft text. Clinicians remain responsible for patient guidance and clinical decisions.

Allowed

  • Summarize structured patient app submissions
  • Highlight red flags from configured rules
  • Draft review notes and patient instructions
  • Prepare referral summaries for clinician approval

Requires clinician approval

  • Diagnosis wording
  • Medication or treatment changes
  • Clinical risk interpretation
  • Patient-facing follow-up instructions

Not allowed

  • Autonomous diagnosis
  • Emergency triage replacement
  • Hidden model decisions
  • Using patient data without clinic authority

Access and requests

Clear routes for security, privacy and data questions.

Clinics can request security information, a data processing agreement review, data export support or help with an incident.