Home/Security

Built for the most sensitive data there is.

Medical records are the most personal information a person has. Our security programme starts from that fact and works backwards.

Certifications

Independently audited.

SOC 2Type II · annual audit
HIPAABAA with every customer
GDPRDPA · Art. 9 safeguards
HDSFrench health-data hosting

Reports and the latest penetration test summary are available under NDA. Request access.

Data residency

Records stay in their region.

EU · eu-west-3

Paris, France

All EU patients. HDS-certified infrastructure. Encryption keys held in an EU-only KMS. No transfer outside the EEA without explicit patient instruction.

US · us-east-1

Virginia, USA

All US patients. HIPAA-eligible services only. Separate account, separate keys, separate on-call rota. Nothing shared with the EU environment except code.

Controls

What we do, specifically.

Encryption everywhereTLS 1.3 in transit. AES-256 at rest. Field-level encryption for identifiers. Keys rotate every 90 days.
Consent-scoped accessAgents receive a token limited to exactly what the patient authorised. Requests outside scope fail at the API, not at policy.
Full audit trailEvery read, write, agent action and model decision is logged immutably and retained for seven years. Customers can stream logs to their SIEM.
Human escalationAgents that leave their script pause and hand off. Specialists work in a monitored environment with no export capability.
Least privilegeProduction access requires hardware keys, is time-boxed, and is reviewed weekly. No standing access to patient data for any employee.
Model isolationNo patient data is used to train foundation models. Fine-tuning uses synthetic and consented, de-identified data only.
Retention & deletionAssembled records are deleted from our systems 30 days after delivery unless the customer extends. Revocation triggers deletion within 24 hours.
Continuous testingAnnual third-party penetration test, quarterly internal red-team on agent behaviour, and a public disclosure programme.
Responsible disclosure

Found something?

Email security@retrievant.example. We acknowledge within one business day, keep you updated, and credit researchers who wish to be named. Please don't access real patient data during testing; use the sandbox.