Trust Center

Everything your security, compliance, or legal team needs to know before trusting our platform.

Updated on

Our legally binding documents — Privacy Policy, Terms of Use, and the rest — exist only in Brazilian Portuguese, under Brazilian law. That is the version that prevails legally.

Overview

Compliance

The laws and standards relevant to diagnos, and where each one really stands.

  • LGPD Brazil's General Data Protection Law

    Implemented

    Brazil's law on the protection of personal data (Law 13,709/2018).

    Legal bases mapped by activity, a record of processing activities maintained, data subject rights served through a dedicated channel, and a publicly named data protection officer.

  • GDPR General Data Protection Regulation

    In progress

    The European Union's data protection regulation (EU 2016/679).

    The architecture and processes meet the regulation — minimization, end-to-end encryption, a record of processing activities, an incident-notification deadline. Still missing: designating the European Union representative required by Article 27.

    Internal reference: ref-020936905
  • HIPAA Health Insurance Portability and Accountability Act

    In progress

    The United States law governing the handling of health data.

    The technical and governance requirements are implemented. The chain of Business Associate Agreements with vendors is partial: signed with Google LLC, in negotiation with Cloudflare, Inc., Modal.com, Sentry, and Anthropic, PBC.

    Internal reference: ref-039841448
  • SOC 2 Service Organization Control 2

    Planned

    An independent audit report on a service provider's security controls.

    The controls are documented and operating, and the public catalog on this page lists them one by one. The independent audit that issues the report has not yet been engaged.

    Internal reference: ref-292230470
  • ISO/IEC 27001

    Planned

    The international standard for information security management systems.

    The policy body follows the standard's structure, but the company is not certified and does not use the seal.

    Internal reference: ref-292230470
  • PCI DSS Payment Card Industry Data Security Standard

    Not applicable

    The security standard for anyone processing payment card data.

    diagnos does not process, transmit, or store card data: payment happens entirely within the environment of the contracted payment provider.

Updates

  1. Trust Center and policy body published

    Policies, manuals, training materials, and compliance records now live in one place, version-controlled alongside the code, with the real status of each control published on this page.

  2. Data protection officer named

    MedDeck now publicly discloses the officer responsible for personal data processing and the direct channel for data subject requests, as required by Art. 41 of Brazil's General Data Protection Law (LGPD).

  3. Business Associate Agreements signed with two subprocessors

    Google LLC and HubSpot, Inc. now operate under a Business Associate Agreement. Agreements with Cloudflare, Inc., Modal.com, and Sentry remain under negotiation.

Documents

The policies and agreements that govern the platform. Public ones open right here; the rest are sent on request.

Public

In Portuguese

On request

Not yet available

  • SOC 2 Report

    Independent audit of security controls.

    The audit has not yet been engaged. The control catalog on this page is the evidence available today.

  • Penetration test report

    Security test conducted by an independent firm.

    Not yet engaged (ref-318001844).

Controls

Each card is a security control with its real status. Whatever is in progress or planned carries the internal reference that records what's missing.

Infrastructure security

  • Implemented

    Encryption key access restricted

    Only authorized personnel with a legitimate business need have privileged access to encryption keys.

  • Implemented

    Unique per-account authentication enforced

    Systems and applications require authentication with unique user identities and no shared credentials.

  • Implemented

    Production application access restricted

    Access to the production application is restricted, by role, to those with a legitimate business need.

  • Implemented

    Access control procedures documented

    The access control policy documents the requirements for granting, changing, and revoking access.

  • Implemented

    Production database access restricted

    Privileged access to production databases is restricted to those with a legitimate business need.

  • Implemented

    Firewall access restricted

    Privileged access to firewall rules is restricted to authorized personnel.

  • Not applicable

    Production operating system access restricted

    Privileged access to the production operating system is restricted to authorized personnel.

  • Implemented

    Production network access restricted

    Privileged access to the production network is restricted to authorized personnel.

  • Implemented

    Access revoked upon termination

    An offboarding checklist ensures access is revoked by a defined deadline when someone leaves the team.

  • Implemented

    Unique network and system authentication enforced

    Production network access requires a unique user identity and a strong, never-shared credential.

Organizational security

  • Implemented

    Security policies established and reviewed

    Information security policies and procedures are documented, approved, and reviewed at least once a year.

  • In progress

    Security awareness training

    The team completes security training upon onboarding and at least once a year thereafter.

    Internal reference: ref-850082595
  • Implemented

    Asset disposal procedures

    Electronic media with confidential information is disposed of per good practice, with a disposal record.

  • Implemented

    Production asset inventory maintained

    A formal inventory of production data assets is maintained and kept up to date.

  • Implemented

    Portable media encrypted

    Portable and removable media devices are encrypted when in use.

  • Implemented

    Code of conduct acknowledged by the team

    The team formally acknowledges a code of conduct at onboarding; violations carry defined consequences.

  • Implemented

    Confidentiality agreement — team

    The team signs a confidentiality agreement during the onboarding process.

  • Implemented

    Confidentiality agreement — contractors

    Contracted personnel sign a confidentiality agreement at the start of the engagement.

  • Implemented

    Performance evaluations conducted

    Formal performance evaluations take place at least once a year.

  • Implemented

    Password and authentication policy enforced

    System components require a credential configured according to company policy.

  • Not applicable

    Visitor procedures

    Visitors sign an entry log, wear a badge, and are escorted in sensitive areas.

Product security

  • Implemented

    Vulnerability reporting channel available

    A public vulnerability channel commits to a first response and no retaliation for good-faith research.

  • Implemented

    Data encryption in use

    Repositories holding sensitive customer data are encrypted at rest.

  • Planned

    Control self-assessments conducted

    Control self-assessments take place at least once a year, with corrective action when something fails.

    Internal reference: ref-292230470
  • Planned

    Penetration testing performed

    Penetration tests are performed at least once a year, with a remediation plan for whatever is found.

    Internal reference: ref-318001844
  • Implemented

    Data transmission encrypted

    Secure transmission protocols encrypt confidential data in transit over public networks.

  • In progress

    Vulnerability and system monitoring

    Formal procedures define vulnerability management and continuous system monitoring.

    Internal reference: ref-395901846

Internal security procedures

  • Implemented

    Risk management program established

    A documented program guides threat identification, risk relevance assessment, and treatment strategy.

  • In progress

    Risk assessment conducted

    Risks are assessed at least yearly, considering regulatory and technological change and fraud potential.

    Internal reference: ref-989475356
  • Implemented

    Third-party agreements established

    All vendors processing data on the company's behalf sign written confidentiality and privacy agreements.

  • Implemented

    Commitments communicated to the customer

    Security and service-level commitments are communicated to the customer in the contractual documents.

  • In progress

    Business continuity and disaster recovery plan established

    Business continuity and disaster recovery plans define how operations continue during an outage.

    Internal reference: ref-430250894
  • Planned

    Continuity plan tested

    The business continuity/disaster recovery plan is tested at least once a year.

    Internal reference: ref-483099250
  • Planned

    Cyber insurance maintained

    Cyber insurance reduces the financial impact of a business interruption caused by an incident.

    Internal reference: ref-503486059
  • In progress

    Configuration management system established

    A configuration management procedure ensures the environment is deployed consistently.

    Internal reference: ref-515864672
  • In progress

    Software development lifecycle established

    A formal development methodology (SDLC) governs system creation, change, and maintenance.

    Internal reference: ref-522570866
  • Planned

    Whistleblower policy established

    An anonymous channel allows reporting potential issues or fraud.

    Internal reference: ref-541016390
  • Planned

    Formal governance oversight

    A board or committee regularly reviews the company's security and privacy posture.

    Internal reference: ref-541429714
  • In progress

    Access reviews conducted

    Access reviews take place at least quarterly, with remediation tracked to completion.

    Internal reference: ref-568129434
  • In progress

    Incident response policy established

    Security and privacy incident response policies and procedures are documented and communicated.

    Internal reference: ref-604727205
  • Not applicable

    Physical access processes established

    Formal processes grant, change, and terminate physical access to facilities that store data.

Data and privacy

  • Implemented

    Backup processes established

    The backup policy defines what is copied, how often, how long it is kept, and how restores are verified.

  • In progress

    Data retention procedures established

    Formal retention and disposal procedures guide the secure storage of company and customer data.

    Internal reference: ref-723541138
  • Implemented

    Data deleted when the customer leaves

    Confidential data is removed from the production environment when a customer stops using the service.

  • In progress

    Data classification policy established

    A classification policy helps ensure confidential data stays restricted to those who need it.

    Internal reference: ref-818673322
  • In progress

    MFA on the team's remote access

    Production systems are only accessed remotely by the team with multi-factor authentication.

    Internal reference: ref-957561724
  • Implemented

    Network segmentation implemented

    The network is segmented to prevent unauthorized access to customer data.

  • Implemented

    Network firewalls in use

    Firewalls are configured to prevent unauthorized access.

  • In progress

    Network and system hardening standards maintained

    Documented hardening standards, based on industry good practice, are reviewed at least once a year.

    Internal reference: ref-993264020

Subprocessors

The companies that process data on diagnos's behalf. None of them receives vault content in the clear.

  • Infrastructure

    Cloudflare, Inc.

    Hosting, content delivery network, edge database, and file storage; transactional email, such as access recovery and the report link sent to the patient; routing of calls to the artificial intelligence model, without storing their content (AI Gateway)

    European Union
  • Infrastructure

    Google LLC

    Account authentication, real-time data sync, and the Gemini artificial intelligence model (Vertex AI) used by the report agents

    United States
  • Media processing

    Modal.com

    Media processing — compression and conversion of uploaded exams

    United States
  • Payments

    Stripe, Inc.

    Payment processing and subscription management

    United States
  • Usage analytics

    PostHog, Inc.

    Product usage analytics

    United States
  • Observability

    Sentry (Functional Software, Inc.)

    Software error monitoring and diagnostics

    European Union
  • Identity verification

    Didit Identity, Inc.

    Identity verification of the legal representative, with biometric comparison between face and document

    European Union
  • Artificial intelligence

    Anthropic, PBC

    Artificial intelligence model for the workspace assistant

    United States
  • Messaging

    Meta Platforms Ireland Ltd.

    Sending, through the official WhatsApp Business Cloud API, the message with the report access link, when the professional chooses that channel; the report content and the password never go through it

    United States
See the full list with the processing agreements

What people ask before trusting the platform

Can MedDeck read the exams and reports in my vault?

As a rule, no. Vault content is encrypted on your device, with keys that only you and the people you authorize hold, and the server stores bytes it cannot open. There are two exceptions, and both are declared. The first is exam media: so that optimized copies can be generated without you being online, the key of each image, video or DICOM file uploaded to an exam, and a key that only opens that exam's optimized copies, are also sealed to the diagnos media processor, which runs on Modal.com. That is why MedDeck is technically able to open those files, their names and the copies — including in response to a request from authorities. The report and the rest of the exam's clinical record, loose drive files, patient records and report templates are outside this exception. The second is the technical file that feeds the image viewer, which stores the patient's name and identifier in the clear, because the viewer's standard format depends on those fields. Bringing it under the same protection as the rest of the vault is in progress (ref-769793806).

Does the artificial intelligence read the image of my exam?

No. The artificial intelligence transcribes and structures what the practitioner dictates or types, and applies the report templates that the practitioner has registered. It does not interpret the image, does not suggest a finding, and does not produce a diagnosis. It is always the healthcare professional who interprets the image and signs the report.

Where is the data stored?

In the United States or the European Union, never in a third region. The file storage and the database that hold exam content sit on infrastructure in the European Union.

What happens if I lose my password and my recovery key?

The vault's content becomes unrecoverable — even by us. That is the direct consequence of encrypting on your device: there is no back door, not for you and not for anyone else. Keep the recovery key with the same care you would give the key to a physical safe.

Do you sell or share data with advertisers?

No. No personal data is sold, rented, or shared for advertising. The complete list of who processes data on diagnos's behalf is on the subprocessors page.

How do I request the Data Processing Agreement?

Write to the privacy channel listed in the Privacy Policy. We provide MedDeck's agreement and the agreements with each subprocessor on the list.

Do you have SOC 2 or ISO 27001 certification?

Not yet. The controls are documented and operating — and they're listed one by one on this page, with the real status of each — but the independent audit that issues the report has not yet been engaged. We would rather say that than display a seal we don't have.

How do I report a security vulnerability?

Through the channel described in the security document. We respond to every good-faith report and take no action against anyone who researches and reports responsibly.