Skip to content

Trust Center

Built to keep as little of your data as possible

Hospitals, students and families will trust Oriaris with their details. Here is what we collect today, what each product line will handle, and what we will never ask you for.

Six commitments

What we will put in writing

01

No patient data, today

We collect no patient data through any product line, form or program. No form asks for a patient name, a claim or a chart

02

Synthetic data for everything public

Every guide, demo case, training example and internship task uses generated data. No intern is given a patient record

03

Only what we need to reply

Our forms ask for contact details and the answers we need to help. Ask us to delete yours and it is gone

04

No cookies, no tracking

No cookies, no analytics and no advertising pixels, on any page. Your browser's storage panel will show you

05

RA 10173 alignment

A Data Privacy Compliance Manual is maintained for National Privacy Commission registration. Our COO is the compliance lead

06

Your people decide

No Oriaris service makes a clinical or coding decision. Your licensed staff do, and nothing reaches a payer without them

Oriaris Core, by design

In, through, and gone

Core is in research and planning. This is how it is being designed to handle a claim.

Received

Encrypted in transit from your HIS

Hashed

Identifiers replaced with a salted SHA-256 digest

Evaluated

Held in volatile memory, never written to disk

Returned

Flag plus evidence sent back to your coder

Gone

Memory released. Only the hash and counters remain

No step in this diagram writes patient data down. That will be a property of the build rather than a policy, and your team will be able to verify it by searching the disk during a technical review.

Read the exact mechanics

On zero retention. Case payloads will be held in volatile memory for the life of one request and released with it. No personal health information will reach a disk, a database, a log line, a cache or an error message. There will be no patient database to breach because there will be no patient database.

On the patient name. Core will accept a name at the boundary for one purpose, computing the salted hash, and discard it inside the same request. It will never be stored, logged or returned, not even inside an error. The demo on this site has no name field at all.

On the audit trail. Each entry will record the rule identifier, the confidence, the human verdict, the timestamp and the anonymization hash. Entries will be appended and never rewritten, and the log will export for your Data Protection Officer or a National Privacy Commission inquiry.

Coordinated disclosure

If you find something, tell us and we will thank you

No legal threat, no gag, and nothing to agree to before you report.

How to reach us

Write to oriaris.health@gmail.com. Include what you found and how to reproduce it. If you want to encrypt, ask and we will send a key

What we commit to

We acknowledge within two business days, tell you our assessment within ten, and tell you when it is fixed

What we ask

Give us reasonable time before publishing, use only synthetic data, and never access, alter or retain anyone else's information

What we will not do

We will not pursue legal action over good faith research conducted within this policy, and we will credit you publicly if you would like that

Not a paid bug bounty: a commitment that your report reaches a human who can act on it.

Bring your hardest privacy question

Whether you run a hospital, apply as an intern or care for a child, ask us anything about your data. Most answers are in the design, not a promise.

Get the free guides