Reltronic does not hold patient data. Not as a matter of policy, but as a consequence of where the software runs. There is no copy to request, no processor to add to your register, and no transfer to justify. Everything below is the detail a security review needs, including the work that is not yet finished.

Reltronic’s position on patient data
Because the platform is bounded and deterministic, an audit can be repeated and will return the same answer. Reviewers are not asked to accept a result that cannot be reproduced.
The platform runs on equipment inside the institution and processes records within the institutional network. There is no Reltronic-held repository of patient information to breach, subpoena or assess.
Patient information is not transmitted to Reltronic, not stored by Reltronic, and not accessible to Reltronic personnel. There is no configuration in which this is otherwise.
Where institutions elect to participate in collaborative research, contributions are statistical rather than individual, participation is opt-in per study, and it can be declined without affecting anything else the platform does.
Compliance and certification
| Framework | Status |
|---|---|
| HIPAA | Deployment model designed so no protected health information is disclosed to Reltronic |
| GDPR / European Health Data Space | Local processing; no cross-border transfer of personal data by Reltronic |
| APPI and comparable localization regimes | Supported through local processing |
| SOC 2 Type II | Not commenced. Scope and timing will be published when an audit is engaged. |
| ISO/IEC 27001 | Not commenced. Institutions requiring certification as a precondition should raise it during scoping. |
| Subprocessor list | Maintained and available on request |
Access
No standing Reltronic access to institutional environments. Support access is granted by the institution, scoped, time-limited and logged.
Encryption
Data encrypted at rest and in transit within the institution. Key custody remains with the institution.
Physical
Equipment protects its contents automatically on detected tampering, preserving a record of the event.
Logging
Tamper-evident activity records available to institutional audit and compliance teams.
Isolated operation
Fully disconnected deployment supported where policy requires it.
Disclosure
Published vulnerability disclosure policy with defined response timelines.
Reporting a vulnerability
Reltronic welcomes reports from security researchers and customer security teams.
Report to client@reltronic.com. Reltronic acknowledges within two business days, provides an assessment within ten business days, and keeps the institution informed through remediation. Reltronic does not pursue legal action against researchers who act in good faith under this policy.
For evaluating security teams
Under mutual non-disclosure Reltronic provides: network and data flow diagrams, deployment and hardening specifications, integration requirements, access control and support model, incident response commitments, subprocessor detail, and completed responses to its own security questionnaire.
