Security engineers and CISOs reviewing the technical architecture
Security architecture
Encryption, authentication, infrastructure and monitoring are the four pillars a review starts with. Here is what each one covers.
The four pillars
Encryption
Data is encrypted at rest with AES-256 and in transit with TLS.
Authentication
Role-based access control and strong authentication gate every session.
Infrastructure
Hosting runs on hardened cloud infrastructure with segmented environments.
Monitoring
Access and anomalies are logged and reviewed on an ongoing basis.
AI-specific safeguards
The intelligence layer adds its own controls on top of the platform's: PII sanitisation before a prompt is sent, prompt-injection defences, a human in the loop on clinical output, and an audit trail on every generated element. Details live on the intelligence pages.
The six questions
- What is it?
- The technical controls that protect records in transit, at rest and while a person is working on them.
- Who is it for?
- Security engineers, CISOs and IT reviewers running a technical due diligence.
- Which problem does it solve?
- A vendor's security page usually lists badges without saying what they actually cover on the platform.
- How does it work?
- AES-256 encryption at rest and TLS in transit, role-based access with strong authentication, infrastructure hosted on hardened cloud providers, and continuous monitoring of access and anomalies.
- How is it different?
- This page states the pillar, not a marketing summary of it; the certification detail sits on the compliance page.
- What is the proof?
- The controls are the same ones audited for ISO/IEC 27001 and SOC 2, listed with scope on the compliance page.
This page is part of a platform of 2,156 clinical and operational capabilities across 8 business domains.
Explore the catalogueContinue
Security contact
Coordinated disclosure and documentation requests: security@on-kare.org.
security@on-kare.org