Trust Center
Built to keep as little of your data as possible
Hospitals, students and families will trust Oriaris with their details. Here is what we collect today, what each product line will handle, and what we will never ask you for.
Six commitments
What we will put in writing
01
No patient data, today
We collect no patient data through any product line, form or program. No form asks for a patient name, a claim or a chart
02
Synthetic data for everything public
Every guide, demo case, training example and internship task uses generated data. No intern is given a patient record
03
Only what we need to reply
Our forms ask for contact details and the answers we need to help. Ask us to delete yours and it is gone
04
No cookies, no tracking
No cookies, no analytics and no advertising pixels, on any page. Your browser's storage panel will show you
05
RA 10173 alignment
A Data Privacy Compliance Manual is maintained for National Privacy Commission registration. Our COO is the compliance lead
06
Your people decide
No Oriaris service makes a clinical or coding decision. Your licensed staff do, and nothing reaches a payer without them
Across every product line
What each line will handle, and how
Oriaris Core, by design
In, through, and gone
Core is in research and planning. This is how it is being designed to handle a claim.
Received
Encrypted in transit from your HIS
Hashed
Identifiers replaced with a salted SHA-256 digest
Evaluated
Held in volatile memory, never written to disk
Returned
Flag plus evidence sent back to your coder
Gone
Memory released. Only the hash and counters remain
No step in this diagram writes patient data down. That will be a property of the build rather than a policy, and your team will be able to verify it by searching the disk during a technical review.
Read the exact mechanics
On zero retention. Case payloads will be held in volatile memory for the life of one request and released with it. No personal health information will reach a disk, a database, a log line, a cache or an error message. There will be no patient database to breach because there will be no patient database.
On the patient name. Core will accept a name at the boundary for one purpose, computing the salted hash, and discard it inside the same request. It will never be stored, logged or returned, not even inside an error. The demo on this site has no name field at all.
On the audit trail. Each entry will record the rule identifier, the confidence, the human verdict, the timestamp and the anonymization hash. Entries will be appended and never rewritten, and the log will export for your Data Protection Officer or a National Privacy Commission inquiry.
Coordinated disclosure
If you find something, tell us and we will thank you
No legal threat, no gag, and nothing to agree to before you report.
How to reach us
Write to oriaris.health@gmail.com. Include what you found and how to reproduce it. If you want to encrypt, ask and we will send a key
What we commit to
We acknowledge within two business days, tell you our assessment within ten, and tell you when it is fixed
What we ask
Give us reasonable time before publishing, use only synthetic data, and never access, alter or retain anyone else's information
What we will not do
We will not pursue legal action over good faith research conducted within this policy, and we will credit you publicly if you would like that
Not a paid bug bounty: a commitment that your report reaches a human who can act on it.
For your DPO
Documents your compliance team will ask for
Bring your hardest privacy question
Whether you run a hospital, apply as an intern or care for a child, ask us anything about your data. Most answers are in the design, not a promise.
