Security & privacy

Your patient data,
under your control

Most AI tools route patient data through third-party language models. Vascue handles raw patient data on self-hosted infrastructure and masks identifiers before any content is passed onward, all under ISO 27001, so confidentiality is the default, not a setting.

  • Self-hosted
  • /
  • PII masked
  • /
  • ISO 27001
  • /
  • No data selling
What that means

Privacy built into the architecture

Not a policy bolted on afterwards. The way the system is built is the way it keeps data safe.

Self-hosted handling

The components that handle raw patient data run inside our controlled environment, not a third-party cloud.

Identifiers masked

Direct identifiers are masked at the boundary before any content is passed onward, so downstream models work on de-identified data.

No raw data to third parties

Raw patient data and direct identifiers are never sent to a third-party model. Only de-identified, minimised content is passed onward.

ISO 27001 certified

Independently audited information-security management, recertified on schedule.

No data selling

We never sell your data or train shared models on it.

Human override

Staff can take over any conversation at any time. The AI never locks you out.

At the privacy boundary

Patient message

WhatsApp, web, or other channels

Identifiers masked

Names, IDs, and contacts removed at the boundary

De-identified content processed

Only masked, minimised data continues onward

Raw patient data and direct identifiers never cross this boundary.

Compliance shouldn't be the thing that slows you down.

Talk with usVisit the Trust Center