AES-256-GCM at rest
Envelope encryption is scoped per owner across all patient data.
Search Shiora
Start typing to search Shiora.
Esc closes search

Trust and security
Named controls protect the record at the service, data and audit layers, with standards and assurance status kept visible.
Architecture and control
The security model combines owner-scoped protection, data-layer enforcement and independently verifiable history.
Envelope encryption is scoped per owner across all patient data.
Access rules are enforced on every service that touches patient data, at the data layer rather than the interface.
SHA-256 audit records are independently verifiable and anchored to a write-once series.
k-anonymity is enforced at the query layer, while secure aggregation reconstructs only the aggregate.
Migration is underway ahead of the 2030 NIST deprecation of RSA-2048 and ECC P-256.
Standards position
Shiora is built to HIPAA technical safeguards and SOC 2 Trust Services Criteria. ISO 27001 certification and ADHICS assessment are underway.
Review standards and certificationsInstitutional review