Skip to content

A specialist examines assurance records in a focused workspace

Trust and security

Security should be inspectable.

Named controls protect the record at the service, data and audit layers, with standards and assurance status kept visible.

Architecture and control

Five controls around the record.

The security model combines owner-scoped protection, data-layer enforcement and independently verifiable history.

Encryption

AES-256-GCM at rest

Envelope encryption is scoped per owner across all patient data.

Implemented
Access

A six-role capability matrix

Access rules are enforced on every service that touches patient data, at the data layer rather than the interface.

Implemented
Audit

Hash-chained, append-only history

SHA-256 audit records are independently verifiable and anchored to a write-once series.

Implemented
Cohorts

Suppression below five distinct people

k-anonymity is enforced at the query layer, while secure aggregation reconstructs only the aggregate.

Implemented
Post-quantum

Hybrid ML-KEM and ML-DSA

Migration is underway ahead of the 2030 NIST deprecation of RSA-2048 and ECC P-256.

Migration underway

Standards position

Built to named criteria.

Shiora is built to HIPAA technical safeguards and SOC 2 Trust Services Criteria. ISO 27001 certification and ADHICS assessment are underway.

Review standards and certifications

Institutional review

Review the control in your deployment context.

Talk to us