TRUST & GOVERNANCE

Trust Framework

Built on transparency, safety-first policies, and rigorous governance.

🛡️
TRUST
HIPAA
DPDP
GDPR
SOC2
AUDIT
LOG
01/04MODULE: CORE POLICY

Abstain-When-Uncertain Policy

HARD RULE

If confidence < threshold → ABSTAIN

  • No reassurance when uncertain
  • No optimization when data is insufficient
  • No forced pathway when confidence is low
  • Always recommend clinician evaluation when abstaining
WHEN WE ABSTAIN
Low signal quality
Conflicting signals
Missing critical data
Unreliable measurements
Insufficient time-series window
02/04MODULE: GOVERNANCE

Governance Framework

Versioned Models
📊

Versioned Models

All ML models are versioned, logged, and auditable

Audit Logs
📝

Audit Logs

Every decision is logged with full traceability

Performance Monitoring
📈

Performance Monitoring

Continuous monitoring for model drift and performance

03/04MODULE: AUDIT LOGS

Audit Log System

LOG STRUCTURE
FieldDescriptionRetention
TimestampExact time of decision7 years
Service IDWhich wing processed the request7 years
Input HashAnonymized input fingerprint7 years
OutputRisk band, confidence, next step7 years
Model VersionExact model version used7 years
Abstain ReasonIf abstained, why7 years
Clinician OverrideIf overridden, by whom and when7 years
04/04MODULE: PRIVACY & SECURITY

Privacy & Security Posture

COMPLIANCE
HIPAAReady
DPDP (India)Aligned
GDPR (EU)Compliant
SOC2Roadmap
SECURITY MEASURES
  • End-to-end encryption for data in transit
  • Encryption at rest for stored data
  • Data minimization principles
  • Regular security audits
  • Access controls and authentication
  • Incident response procedures
DATA ETHICS PRINCIPLES
  • • Collect only what is required
  • • Process only for stated purpose
  • • Retain only as long as needed
  • • Delete on request
  • • Never monetize patient data
  • • No diagnosis language to patients
  • • No fear-based outputs
  • • Clear next-step framing