BaetylOS← Back to homepage

Security & data handling

An overview of the documented security design and the questions to resolve for each hospital deployment.

Infrastructure and encryption

The March 2026 security whitepaper describes isolated Azure infrastructure, private database and AI endpoints, encrypted hospital connectivity, TLS 1.2+ in transit, and AES-256 at rest. These are documented design statements; the current deployed configuration should be verified during security review.

Use of clinical data

The whitepaper states that Baetyl does not use customer data for model training or fine-tuning. AI requests are scoped to relevant patient context. Temporary processed data is described as being cleaned up after report delivery; audit logging is a separate consideration. Exact retention periods and deletion responsibilities must be agreed for the deployment.

Identity, permissions, and audit

The integration materials call for verified clinician identity mappings and review of permitted operations. Confirm user deactivation, service credentials, access roles, audit availability, and handling of restricted records before clinical use.

Contracts and assurance

The whitepaper describes HIPAA alignment and hospital-specific BAA support. It lists SOC 2 Type II as planned and HITRUST as under evaluation. This page does not claim those certifications. Request current evidence during hospital security and contracting review.

About this website prototype

The examples are synthetic. This website does not accept clinical records or operate the hospital reporting workflow. Private site access is provided by the hosting service. This overview is not a privacy policy or a description of every hosting-provider data practice.

Book a pilot ↗Frequently asked questions →