Skip to content
MedJourney International Patient Operations Platform Request a Demo
Security

What we have today, and what we are working on

This page is written for the security and data protection reviewers on your side. The two lists below are deliberately separate: everything under "Available today" is running in the product, and everything under "On the roadmap" is not.

Available

Available today

These controls are implemented in the product and can be verified during a technical review.

  • Encryption

    Traffic is served over TLS. Identity-bearing fields such as passport numbers are additionally encrypted at the column level, so they are unreadable in a database backup.

  • Role-based access

    Permissions are expressed as policies rather than role name checks: patient management, medical assessment, content approval, compliance tools and clinic administration are separate rights.

  • Two-factor authentication

    TOTP-based second factor for staff accounts. It can be enforced platform-wide or per hospital; when enforced, a user cannot enter the panel before completing enrolment.

  • Audit log

    Every write operation produces an audit record: who, when, which entity, and the old and new values. Sensitive fields such as password hashes are masked in the record itself.

  • Hospital data isolation

    Every row carries the hospital identifier and a global query filter enforces it. A hospital can additionally be moved to its own database without a code change.

  • Deletion and anonymisation

    Health data is never hard-deleted; a deletion request anonymises the record and marks it deleted, so statutory retention obligations and the patient's request can both be satisfied.

  • Consent management

    Consent texts are versioned and consent records are bound to the version the patient approved. Records are immutable — the panel offers no way to edit or delete them.

  • Retention and cleanup

    Operational data such as verification codes, refresh tokens and inactive devices is purged on a schedule. Health and legal records are never purged automatically; they surface for review.

Planned

On the roadmap

These are not in place today. They are listed because procurement teams ask about them and an honest answer is more useful than a vague one. We can share indicative timing in a call.

  • SOC 2 Type II

    No audit has been performed and no report exists. Planned once the platform's operational history is long enough for a Type II observation window.

  • Independent penetration test

    No third-party test report exists yet. Planned before the first large-scale deployment.

  • HIPAA package and BAA

    We do not currently sign Business Associate Agreements. Required for US-based operations and planned alongside a US data residency option.

  • Regional data residency

    Data currently resides in a single region. EU and US hosting options are planned; a hospital can already be placed in its own database as an interim measure.

  • PIPA and other regional analyses

    Formal assessments for jurisdictions such as South Korea have not been completed.

Technical review

If your security team needs architecture detail, a data flow description or answers to a vendor questionnaire, request a demo and note it in the message — we will arrange a session with the engineering side.

Request a Demo