Security & Trust
Built for regulated data
Security is the architecture, not a badge. Here is how the platform is designed to earn the trust of healthcare and life-sciences teams.
De-identified data by design
The platform is built to work with de-identified data. Identifiers are removed at the source before data reaches us, and every ingested item passes a verification gate that scans for residual identifiers and quarantines anything that fails.
Encryption everywhere
Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Secrets are held in a managed secret store, never in source code.
Least-privilege access control
Role-based access control governs every action. Annotators see only their assigned work; reviewers see the QA queue; customers see only their own organization’s data. Cross-tenant access is not possible through the application.
Immutable audit trail
Login, file access, downloads, role changes, assignments, annotation submissions, QA decisions, and exports are recorded to an append-only audit log.
Provenance & data ownership
Model proposals, expert corrections, ontology mappings, and QA decisions stay linked to the dataset they came from. Your labeled data is yours — versioned, exportable, and never locked to a single model or vendor.
Deployment in your environment
Run it as our SaaS, in your own cloud with your database, or fully on-premises — so regulated data can stay inside your infrastructure.
Compliance posture
We build to a HIPAA-aware control set from day one and keep protected health information out of the platform by requiring de-identification at the source. Formal attestations (e.g. SOC 2 Type II, and HITRUST for enterprise health-plan work) are on our roadmap and pursued as enterprise engagements require them. For a current security overview, a data-use agreement, or BAA discussion, contact us.
Request our security overviewFound a vulnerability? Please report it responsibly to contactus@medicalgradedata.com.