Trust Center
Everything your security, compliance, or legal team needs to know before trusting our platform.
[email protected]Updated on
Our legally binding documents — Privacy Policy, Terms of Use, and the rest — exist only in Brazilian Portuguese, under Brazilian law. That is the version that prevails legally.
Overview
Compliance
The laws and standards relevant to diagnos, and where each one really stands.
-
LGPD Brazil's General Data Protection Law
ImplementedBrazil's law on the protection of personal data (Law 13,709/2018).
Legal bases mapped by activity, a record of processing activities maintained, data subject rights served through a dedicated channel, and a publicly named data protection officer.
-
GDPR General Data Protection Regulation
In progressThe European Union's data protection regulation (EU 2016/679).
The architecture and processes meet the regulation — minimization, end-to-end encryption, a record of processing activities, an incident-notification deadline. Still missing: designating the European Union representative required by Article 27.
Internal reference: ref-020936905 -
HIPAA Health Insurance Portability and Accountability Act
In progressThe United States law governing the handling of health data.
The technical and governance requirements are implemented. The chain of Business Associate Agreements with vendors is partial: signed with Google LLC, in negotiation with Cloudflare, Inc., Modal.com, Sentry, and Anthropic, PBC.
Internal reference: ref-039841448 -
SOC 2 Service Organization Control 2
PlannedAn independent audit report on a service provider's security controls.
The controls are documented and operating, and the public catalog on this page lists them one by one. The independent audit that issues the report has not yet been engaged.
Internal reference: ref-292230470 -
ISO/IEC 27001
PlannedThe international standard for information security management systems.
The policy body follows the standard's structure, but the company is not certified and does not use the seal.
Internal reference: ref-292230470 -
PCI DSS Payment Card Industry Data Security Standard
Not applicableThe security standard for anyone processing payment card data.
diagnos does not process, transmit, or store card data: payment happens entirely within the environment of the contracted payment provider.
Controls
Our security controls, by area. Pick one to see each control.
- Infrastructure security
- Organizational security
- Product security
- Internal security procedures
- Data and privacy
Updates
-
Trust Center and policy body published
Policies, manuals, training materials, and compliance records now live in one place, version-controlled alongside the code, with the real status of each control published on this page.
-
Data protection officer named
MedDeck now publicly discloses the officer responsible for personal data processing and the direct channel for data subject requests, as required by Art. 41 of Brazil's General Data Protection Law (LGPD).
-
Business Associate Agreements signed with two subprocessors
Google LLC and HubSpot, Inc. now operate under a Business Associate Agreement. Agreements with Cloudflare, Inc., Modal.com, and Sentry remain under negotiation.
Documents
The policies and agreements that govern the platform. Public ones open right here; the rest are sent on request.
Public
In Portuguese
- Privacy Policy What data we handle, under what legal basis, for how long, and what your rights are.
- Terms of Use What the platform does, what it deliberately does not do, and who is responsible for the medical report.
- How diagnos protects your data Security architecture, the zero-knowledge vault, and what we're still building.
- Subprocessors Who processes data on diagnos's behalf, for what purpose, and in which region.
- Law Enforcement Requests What we hand over under a valid court order, and what is technically impossible to hand over.
- Cookie Policy What is stored in your browser, for how long, and how to decline.
On request
-
Data Processing Agreement
The agreement governing the processing of personal data between your organization and MedDeck, plus the agreements with each subprocessor.
Request through the privacy channel -
Internal security policies
Access control, incident response, continuity, encryption, classification, and data retention.
Request through the privacy channel
Not yet available
-
SOC 2 Report
Independent audit of security controls.
The audit has not yet been engaged. The control catalog on this page is the evidence available today.
-
Penetration test report
Security test conducted by an independent firm.
Not yet engaged (ref-318001844).
Controls
Each card is a security control with its real status. Whatever is in progress or planned carries the internal reference that records what's missing.
Infrastructure security
- Implemented
Encryption key access restricted
Only authorized personnel with a legitimate business need have privileged access to encryption keys.
- Implemented
Unique per-account authentication enforced
Systems and applications require authentication with unique user identities and no shared credentials.
- Implemented
Production application access restricted
Access to the production application is restricted, by role, to those with a legitimate business need.
- Implemented
Access control procedures documented
The access control policy documents the requirements for granting, changing, and revoking access.
- Implemented
Production database access restricted
Privileged access to production databases is restricted to those with a legitimate business need.
- Implemented
Firewall access restricted
Privileged access to firewall rules is restricted to authorized personnel.
- Not applicable
Production operating system access restricted
Privileged access to the production operating system is restricted to authorized personnel.
- Implemented
Production network access restricted
Privileged access to the production network is restricted to authorized personnel.
- Implemented
Access revoked upon termination
An offboarding checklist ensures access is revoked by a defined deadline when someone leaves the team.
- Implemented
Unique network and system authentication enforced
Production network access requires a unique user identity and a strong, never-shared credential.
Organizational security
- Implemented
Security policies established and reviewed
Information security policies and procedures are documented, approved, and reviewed at least once a year.
- In progress
Security awareness training
The team completes security training upon onboarding and at least once a year thereafter.
Internal reference: ref-850082595 - Implemented
Asset disposal procedures
Electronic media with confidential information is disposed of per good practice, with a disposal record.
- Implemented
Production asset inventory maintained
A formal inventory of production data assets is maintained and kept up to date.
- Implemented
Portable media encrypted
Portable and removable media devices are encrypted when in use.
- Implemented
Code of conduct acknowledged by the team
The team formally acknowledges a code of conduct at onboarding; violations carry defined consequences.
- Implemented
Confidentiality agreement — team
The team signs a confidentiality agreement during the onboarding process.
- Implemented
Confidentiality agreement — contractors
Contracted personnel sign a confidentiality agreement at the start of the engagement.
- Implemented
Performance evaluations conducted
Formal performance evaluations take place at least once a year.
- Implemented
Password and authentication policy enforced
System components require a credential configured according to company policy.
- Not applicable
Visitor procedures
Visitors sign an entry log, wear a badge, and are escorted in sensitive areas.
Product security
- Implemented
Vulnerability reporting channel available
A public vulnerability channel commits to a first response and no retaliation for good-faith research.
- Implemented
Data encryption in use
Repositories holding sensitive customer data are encrypted at rest.
- Planned
Control self-assessments conducted
Control self-assessments take place at least once a year, with corrective action when something fails.
Internal reference: ref-292230470 - Planned
Penetration testing performed
Penetration tests are performed at least once a year, with a remediation plan for whatever is found.
Internal reference: ref-318001844 - Implemented
Data transmission encrypted
Secure transmission protocols encrypt confidential data in transit over public networks.
- In progress
Vulnerability and system monitoring
Formal procedures define vulnerability management and continuous system monitoring.
Internal reference: ref-395901846
Internal security procedures
- Implemented
Risk management program established
A documented program guides threat identification, risk relevance assessment, and treatment strategy.
- In progress
Risk assessment conducted
Risks are assessed at least yearly, considering regulatory and technological change and fraud potential.
Internal reference: ref-989475356 - Implemented
Third-party agreements established
All vendors processing data on the company's behalf sign written confidentiality and privacy agreements.
- Implemented
Commitments communicated to the customer
Security and service-level commitments are communicated to the customer in the contractual documents.
- In progress
Business continuity and disaster recovery plan established
Business continuity and disaster recovery plans define how operations continue during an outage.
Internal reference: ref-430250894 - Planned
Continuity plan tested
The business continuity/disaster recovery plan is tested at least once a year.
Internal reference: ref-483099250 - Planned
Cyber insurance maintained
Cyber insurance reduces the financial impact of a business interruption caused by an incident.
Internal reference: ref-503486059 - In progress
Configuration management system established
A configuration management procedure ensures the environment is deployed consistently.
Internal reference: ref-515864672 - In progress
Software development lifecycle established
A formal development methodology (SDLC) governs system creation, change, and maintenance.
Internal reference: ref-522570866 - Planned
Whistleblower policy established
An anonymous channel allows reporting potential issues or fraud.
Internal reference: ref-541016390 - Planned
Formal governance oversight
A board or committee regularly reviews the company's security and privacy posture.
Internal reference: ref-541429714 - In progress
Access reviews conducted
Access reviews take place at least quarterly, with remediation tracked to completion.
Internal reference: ref-568129434 - In progress
Incident response policy established
Security and privacy incident response policies and procedures are documented and communicated.
Internal reference: ref-604727205 - Not applicable
Physical access processes established
Formal processes grant, change, and terminate physical access to facilities that store data.
Data and privacy
- Implemented
Backup processes established
The backup policy defines what is copied, how often, how long it is kept, and how restores are verified.
- In progress
Data retention procedures established
Formal retention and disposal procedures guide the secure storage of company and customer data.
Internal reference: ref-723541138 - Implemented
Data deleted when the customer leaves
Confidential data is removed from the production environment when a customer stops using the service.
- In progress
Data classification policy established
A classification policy helps ensure confidential data stays restricted to those who need it.
Internal reference: ref-818673322 - In progress
MFA on the team's remote access
Production systems are only accessed remotely by the team with multi-factor authentication.
Internal reference: ref-957561724 - Implemented
Network segmentation implemented
The network is segmented to prevent unauthorized access to customer data.
- Implemented
Network firewalls in use
Firewalls are configured to prevent unauthorized access.
- In progress
Network and system hardening standards maintained
Documented hardening standards, based on industry good practice, are reviewed at least once a year.
Internal reference: ref-993264020
Subprocessors
The companies that process data on diagnos's behalf. None of them receives vault content in the clear.
-
Infrastructure
Cloudflare, Inc.
Hosting, content delivery network, edge database, and file storage; transactional email, such as access recovery and the report link sent to the patient; routing of calls to the artificial intelligence model, without storing their content (AI Gateway)
European Union -
Infrastructure
Google LLC
Account authentication, real-time data sync, and the Gemini artificial intelligence model (Vertex AI) used by the report agents
United States -
Media processing
Modal.com
Media processing — compression and conversion of uploaded exams
United States -
Payments
Stripe, Inc.
Payment processing and subscription management
United States -
Usage analytics
PostHog, Inc.
Product usage analytics
United States -
Observability
Sentry (Functional Software, Inc.)
Software error monitoring and diagnostics
European Union -
Identity verification
Didit Identity, Inc.
Identity verification of the legal representative, with biometric comparison between face and document
European Union -
Artificial intelligence
Anthropic, PBC
Artificial intelligence model for the workspace assistant
United States -
Messaging
Meta Platforms Ireland Ltd.
Sending, through the official WhatsApp Business Cloud API, the message with the report access link, when the professional chooses that channel; the report content and the password never go through it
United States
What people ask before trusting the platform
Can MedDeck read the exams and reports in my vault?
As a rule, no. Vault content is encrypted on your device, with keys that only you and the people you authorize hold, and the server stores bytes it cannot open. There are two exceptions, and both are declared. The first is exam media: so that optimized copies can be generated without you being online, the key of each image, video or DICOM file uploaded to an exam, and a key that only opens that exam's optimized copies, are also sealed to the diagnos media processor, which runs on Modal.com. That is why MedDeck is technically able to open those files, their names and the copies — including in response to a request from authorities. The report and the rest of the exam's clinical record, loose drive files, patient records and report templates are outside this exception. The second is the technical file that feeds the image viewer, which stores the patient's name and identifier in the clear, because the viewer's standard format depends on those fields. Bringing it under the same protection as the rest of the vault is in progress (ref-769793806).
Does the artificial intelligence read the image of my exam?
No. The artificial intelligence transcribes and structures what the practitioner dictates or types, and applies the report templates that the practitioner has registered. It does not interpret the image, does not suggest a finding, and does not produce a diagnosis. It is always the healthcare professional who interprets the image and signs the report.
Where is the data stored?
In the United States or the European Union, never in a third region. The file storage and the database that hold exam content sit on infrastructure in the European Union.
What happens if I lose my password and my recovery key?
The vault's content becomes unrecoverable — even by us. That is the direct consequence of encrypting on your device: there is no back door, not for you and not for anyone else. Keep the recovery key with the same care you would give the key to a physical safe.
Do you sell or share data with advertisers?
No. No personal data is sold, rented, or shared for advertising. The complete list of who processes data on diagnos's behalf is on the subprocessors page.
How do I request the Data Processing Agreement?
Write to the privacy channel listed in the Privacy Policy. We provide MedDeck's agreement and the agreements with each subprocessor on the list.
Do you have SOC 2 or ISO 27001 certification?
Not yet. The controls are documented and operating — and they're listed one by one on this page, with the real status of each — but the independent audit that issues the report has not yet been engaged. We would rather say that than display a seal we don't have.
How do I report a security vulnerability?
Through the channel described in the security document. We respond to every good-faith report and take no action against anyone who researches and reports responsibly.