SeuSive
Security
Last updated June 15, 2026
SeuSive is built for clinics that can't afford to be wrong. Security and clinical safety are constraints in the product, not badges on a page.
The clinician stays in control
- Clinician review is required — nothing reaches the chart without a human decision.
- No autonomous diagnosis, prescribing, or emergency dispatch.
- Source, reviewer, and authority are shown on every clinical output.
Data protection
- Encryption in transit (TLS) and at rest.
- Least-privilege access, scoped credentials, and managed secrets.
- Separation between environments; production data is never used in demos or development.
Tenancy & auditability
Each clinic's data is isolated per tenant. A full audit trail records who saw what, when, and what they decided — so every output is accountable end to end.
Hosting & residency
We run on reputable cloud infrastructure. Data residency is configurable per marketthrough country packs, so data stays in the region your jurisdiction requires.
The PHI gate
No production patient data is processed until tenancy, hosting, retention, and access controls are configured and approved with your clinic.
Compliance posture
SeuSive is built to align with HIPAA and GDPR, with residency and controls configurable per deployment. We describe this as aware / ready / configurable — not as a certification. We provide a Data Processing Agreement (DPA), and a Business Associate Agreement (BAA) for US HIPAA-covered entities, on request. Formal third-party attestations are on our roadmap and will be listed here when complete.
Sub-processors
Infrastructure sub-processors are vetted and contractually bound. A current list is available on request.
Responsible disclosure
Found a vulnerability? Email [email protected]. We welcome good-faith research and won't pursue researchers who act responsibly and avoid accessing real patient data.
Contact
Security or compliance questions? Email [email protected], or read how we handle data on the Privacy page.
This page is a plain-language summary, not a contract. For binding terms — including our Data Processing Agreement (DPA) and, for US HIPAA-covered entities, a Business Associate Agreement (BAA) — contact [email protected].