diagnos
The Python library behind the vault: import it, touch `vault.patients`, and unlock happens on its own — encrypted in your own process, start to finish.
Dev Center
A Python SDK, a CLI, and an mTLS-authenticated REST API — keys are born and live only in your process's memory, and the server never sees anything but ciphertext.
Open source packages
We offer a Python SDK, a CLI that runs on Windows, Mac, and Linux, and a RESTful API ready for a container or Kubernetes environment — all while keeping end-to-end encryption (E2E), and all of it open source under the Apache 2.0 license.
The Python library behind the vault: import it, touch `vault.patients`, and unlock happens on its own — encrypted in your own process, start to finish.
The whole SDK, straight in your terminal: `diagnos login` handles enrollment, and the patients, exams, and files commands take it from there.
A thin REST facade over the same SDK, for teams that speak HTTP instead of Python — authenticated only by mTLS certificate.
The license grants commercial use, modification, and redistribution, with an express patent grant — the only ask is preserving the copyright notice and flagging the changes you make. We're not promising support, a public roadmap, or a contribution process: this is open source, not a product with a support contract.
Get building
Pick a package and an install method — the commands below are exactly what the repository's READMEs verify.
Every command below needs a DIAGNOS_API_TOKEN, issued by a workspace admin. How to get one
pip install diagnosfrom diagnos import Diagnos
with Diagnos() as vault:
for row in vault.patients.list():
patient = vault.patients.get(row.document_id)
print(patient.record.legal_name)pip install "diagnos @ git+https://github.com/diagnos-tech/integration@develop#subdirectory=apps/sdk"from diagnos import Diagnos
with Diagnos() as vault:
for row in vault.patients.list():
patient = vault.patients.get(row.document_id)
print(patient.record.legal_name)Builds the Rust enclave during install — needs cargo and rustup on PATH.
git clone https://github.com/diagnos-tech/integration && cd integration
make sync
make checkBuilds the Rust enclave during install — needs cargo and rustup on PATH.
pipx install diagnos-clidiagnos logindiagnos --json patients list --group sg_oncology | jq '.items[].document_id'The session is never written to disk: without OpenBao configured, every new invocation enrolls all over again.
pipx install "diagnos-cli @ git+https://github.com/diagnos-tech/integration@develop#subdirectory=apps/cli" \
--preinstall "diagnos @ git+https://github.com/diagnos-tech/integration@develop#subdirectory=apps/sdk"diagnos logindiagnos --json patients list --group sg_oncology | jq '.items[].document_id'The session is never written to disk: without OpenBao configured, every new invocation enrolls all over again.
docker build -f apps/api/Dockerfile -t diagnos-api .docker run --rm -p 8443:8443 --cap-add=IPC_LOCK \
-e DIAGNOS_API_TOKEN=apikey-… \
-e DIAGNOS_API_MTLS_CA_FILE=/certs/clients-ca.pem \
-e DIAGNOS_API_TLS_CERT_FILE=/certs/server.pem \
-e DIAGNOS_API_TLS_KEY_FILE=/certs/server-key.pem \
-v $PWD/certs:/certs:ro diagnos-api--cap-add=IPC_LOCK lets the Rust enclave lock keys in RAM past the 64 KiB default; without it, the container still starts in best-effort mode.
cd apps/api/deploy/compose
cp .env.example .env
docker compose upBrings up OpenBao and the API together, in the same compose file.
kubectl apply -k apps/api/deploy/k8sOne replica only: the SDK session is per-process. Scaling needs OpenBao and one service account per replica.
Access control
DIAGNOS_API_TOKEN identifies a service account and its workspace, and is issued by a workspace admin. On its own, it unlocks nothing — the human approval from the three steps below is what does.
The full reference is public — reach it through the GitHub repository or the documentation below, no approval required. To authenticate calls, create a DIAGNOS_API_TOKEN under Settings → Service accounts, inside your workspace.
or write to [email protected]
Zero trust
No process reads anything on its own: enrollment trades keys and waits for a person to approve — live, or ahead of time.