Skip to content

Trust architecture

The safeguards — and
what they mean for you.

Most security pages are adjectives. This one explains the practical boundaries: who can reach a record, what gets logged, where AI stops, and what a patient can take back.

CLINICAL AUDIT · APPEND-ONLYWRITING

11:24:07report.readdr.mehta · NMD-2481 · treatment

11:24:52report.signdr.mehta · NMD-2481 · granted

11:26:14report.releasesystem · NMD-2481 · patient app

11:26:15image.accesspatient · NMD-2481 · granted

No delete path. No update path. The row that was written is the row you read back in the review.

Six guards

What actually stops what.

Each safeguard has a clear operational consequence. Your IT and compliance teams can review these controls against the workflows they care about.

Access is scoped to a facility

A user can reach a record only when they hold an active membership in the facility that owns it. The same rule applies regardless of which approved workflow they use.

Facility-level authorization

The audit trail is append-only

Reads, creates, updates, downloads, and exports append an event carrying the facility, the actor, the patient, the purpose, the outcome, and a correlation reference. The application can add events but cannot rewrite them.

Append-only audit history

Radiology intelligence stays clinician-led

NexaMed's proprietary algorithms provide an active second read and have reached up to 87% on internal evaluation benchmarks. A radiologist reviews the analysis and signs the final report.

Active assistance with clinician sign-off

Document intake fails closed

A patient upload that is unavailable, ambiguous, infected, or fails its checksum never becomes downloadable, never gets extracted, and never reaches automated analysis. Uncertainty resolves to refusal, not to a best guess.

Fail-closed document intake

Patient AI runs on minimum necessary context

The patient copilot uses only the context the patient is allowed to access, minimizes retained data, keeps patient health information out of application logs, and requires approved data controls before production use.

Minimum-necessary patient context

Patients can take it back

Device integrations retain consented daily aggregates only, deletion is patient-initiated with a 30-day restore window, and copilot history is encrypted and expires on a bounded purge.

Patient-controlled retention

What we don't claim

The part every other vendor leaves off.

You're going to find this out in diligence anyway. You should find it out from us, on our own website, before you've spent three weeks on a procurement.

Building toward ABDM integration

We are building NexaMed in line with ABDM documentation and integration requirements. The foundations — facility tenancy, HFR and HIP metadata, encrypted ABHA linkage, and a consent state model — are already in place, and our ABDM registration is currently in progress. Live ABHA verification and health-record exchange will be enabled once registration and the required approvals are complete.

Our radiology AI remains decision support

It is an active, proprietary second read with internal evaluation scores of up to 87%. It does not replace radiologist judgment or final sign-off, and the internal score is not presented as independent clinical validation.

We don't publish an uptime number

Not until we've run long enough at real hospital load to have one worth putting in a contract. We'd rather show you our incident posture in the review than print a nine we haven't earned.

Unapproved clinical scoring stays unavailable

A scoring tool stays out of clinical use until a clinician approves the rubric behind it. A health score nobody clinical signed off on is a liability with a nice gradient on it.

Your data stays yours

The exit is part of the product.

Every hospital that has been trapped in a system knows the tell: the data only comes out in a format the vendor invented. So here's ours, in the open.

FHIR R4 document bundles

A consultation exports as a standard bundle — patient, organization, practitioner, encounter, diagnosis, prescriptions, investigations, diagnostic reports. Artifacts carry the FHIR version, the profile version, the source version, and a deterministic payload fingerprint.

Standards-based portability

Built for ABDM, honest about the date

Plain ABHA numbers are never persisted, logged, or put in a URL — only an encrypted reference. When our registration completes, the exchange turns on against foundations that were built for it from the start, rather than bolted on in a panic.

Encrypted identity linkage

Authentication confirms who signed in, and that's all we let it answer. Clinical records keep their own identity boundary, so a login provider never quietly becomes the patient index.

Identity and clinical records remain separate

Next step

Send your toughest security reviewer.

Bring your IT and compliance team. We'll walk through access, audit history, patient-data boundaries, and how clinical decision support is reviewed and signed off — using the workflows they want to challenge.