Trust Center

Reltronic does not hold patient data. Not as a matter of policy, but as a consequence of where the software runs. There is no copy to request, no processor to add to your register, and no transfer to justify. Everything below is the detail a security review needs, including the work that is not yet finished.

Reltronic's position on patient data and the six elements of its security posture.

Reltronic’s position on patient data

Because the platform is bounded and deterministic, an audit can be repeated and will return the same answer. Reviewers are not asked to accept a result that cannot be reproduced.

The platform runs on equipment inside the institution and processes records within the institutional network. There is no Reltronic-held repository of patient information to breach, subpoena or assess.

Patient information is not transmitted to Reltronic, not stored by Reltronic, and not accessible to Reltronic personnel. There is no configuration in which this is otherwise.

Where institutions elect to participate in collaborative research, contributions are statistical rather than individual, participation is opt-in per study, and it can be declined without affecting anything else the platform does.

Compliance and certification

FrameworkStatus
HIPAADeployment model designed so no protected health information is disclosed to Reltronic
GDPR / European Health Data SpaceLocal processing; no cross-border transfer of personal data by Reltronic
APPI and comparable localization regimesSupported through local processing
SOC 2 Type IINot commenced. Scope and timing will be published when an audit is engaged.
ISO/IEC 27001Not commenced. Institutions requiring certification as a precondition should raise it during scoping.
Subprocessor listMaintained and available on request

Access

No standing Reltronic access to institutional environments. Support access is granted by the institution, scoped, time-limited and logged.

Encryption

Data encrypted at rest and in transit within the institution. Key custody remains with the institution.

Physical

Equipment protects its contents automatically on detected tampering, preserving a record of the event.

Logging

Tamper-evident activity records available to institutional audit and compliance teams.

Isolated operation

Fully disconnected deployment supported where policy requires it.

Disclosure

Published vulnerability disclosure policy with defined response timelines.

Reporting a vulnerability

Reltronic welcomes reports from security researchers and customer security teams.

Report to client@reltronic.com. Reltronic acknowledges within two business days, provides an assessment within ten business days, and keeps the institution informed through remediation. Reltronic does not pursue legal action against researchers who act in good faith under this policy.

For evaluating security teams

Under mutual non-disclosure Reltronic provides: network and data flow diagrams, deployment and hardening specifications, integration requirements, access control and support model, incident response commitments, subprocessor detail, and completed responses to its own security questionnaire.