Security
Security is not a checklist we attach at the end. It is part of how the platform is built. Here is our posture, in plain language.
Last updated: 11 July 2026
We hold clinical data to a high bar because the trust behind it is hard to earn and easy to lose. The following describes the controls that protect data handled through our platform and partnerships.
Encryption
Data is encrypted in transit using modern protocols and at rest using strong, industry-standard encryption. Encryption keys are managed carefully, rotated, and never committed to source code.
Least-privilege access
Access is role-based and granted on a need-to-know basis. Administrative access is limited, reviewed, and logged. We favor short-lived credentials and strong authentication for anyone who can touch data.
Isolation
Data from different institutions is kept separate and isolated. We do not commingle partner data, and one partner’s data is never used to serve another without explicit, written agreement.
Auditability
The platform is built so that its actions and outputs can be traced and reviewed. That turns questions about what happened into something we can answer with evidence, rather than a guess.
Secure development
- Code review and version control for all changes.
- Automated checks in our development pipeline.
- Careful management of dependencies and credentials.
- A clear separation between what is public and what is protected.
Privacy by design
The platform is built to operate without holding on to patient-identifying information, and patient videos are not permanently stored as part of routine operation. See our Data Governance page.
Incident response
We maintain an incident-response process and will notify affected partners without undue delay in the event of a security incident, consistent with our contractual and legal obligations.
Responsible disclosure
If you believe you have found a security vulnerability, we want to hear from you. Please email security@trigone.net with details and steps to reproduce. We commit to acknowledging reports promptly, working in good faith to resolve valid issues, and not pursuing action against researchers who disclose responsibly and avoid privacy violations or service disruption.
Compliance posture
As an early-stage company, we are building toward formal certifications and a quality-management system aligned with medical-device software standards. See our Regulatory Roadmap. We are transparent about where we are on that journey and welcome your due diligence.
Questions about this document? Contact contact@trigone.net. For related policies, see our Privacy, Security, and Data Governance pages.