Trust / Security

Security whitepaper.

A plain-language summary of the controls Medi Prompt operates across infrastructure, application, data, and organizational security.

Infrastructure

  • Isolated tenancy

    Per-tenant data siloing with strong logical boundaries.

  • Hardened images

    Minimal base images, continuous vulnerability scanning, and automated patching.

  • Network posture

    Private networking by default, mTLS between services, WAF at the edge.

Application

  • Authentication

    SSO/SAML, MFA, and short-lived tokens with rotation.

  • Authorization

    Granular role-based access with fine-grained scopes for API tokens.

  • Secure SDLC

    Code review, dependency scanning, and secrets management on every merge.

Data

  • Zero-retention AI

    Model inference operates on a zero-retention basis by default.

  • Per-tenant siloing

    Cryptographic isolation between clinics and workspaces.

  • No training on PHI

    Patient data is never used in foundational training.

Organizational

Security is a team behavior, not a checkbox. Background checks, security training, incident response runbooks, and annual third-party penetration testing keep the humans as sharp as the systems.

Coordinated disclosure at security@mediprompt.health. We acknowledge within one business day and update reporters through remediation.