Security & Trust

Built for regulated data

Security is the architecture, not a badge. Here is how the platform is designed to earn the trust of healthcare and life-sciences teams.

De-identified data by design

The platform is built to work with de-identified data. Identifiers are removed at the source before data reaches us, and every ingested item passes a verification gate that scans for residual identifiers and quarantines anything that fails.

Encryption everywhere

Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Secrets are held in a managed secret store, never in source code.

Least-privilege access control

Role-based access control governs every action. Annotators see only their assigned work; reviewers see the QA queue; customers see only their own organization’s data. Cross-tenant access is not possible through the application.

Immutable audit trail

Login, file access, downloads, role changes, assignments, annotation submissions, QA decisions, and exports are recorded to an append-only audit log.

Provenance & data ownership

Model proposals, expert corrections, ontology mappings, and QA decisions stay linked to the dataset they came from. Your labeled data is yours — versioned, exportable, and never locked to a single model or vendor.

Deployment in your environment

Run it as our SaaS, in your own cloud with your database, or fully on-premises — so regulated data can stay inside your infrastructure.

Compliance posture

We build to a HIPAA-aware control set from day one and keep protected health information out of the platform by requiring de-identification at the source. Formal attestations (e.g. SOC 2 Type II, and HITRUST for enterprise health-plan work) are on our roadmap and pursued as enterprise engagements require them. For a current security overview, a data-use agreement, or BAA discussion, contact us.

Request our security overview

Found a vulnerability? Please report it responsibly to contactus@medicalgradedata.com.