
SHOMA® AI
Health API
We designed the platform with a zero-trust, zero-retention architecture specifically for healthcare environments.
• End-to-end encryption (AES-256) for all data in transit and during processing • Client-side envelope encryption option available • Strict zero data retention: all clinical documents and generated reports are permanently deleted immediately after delivery • No patient data is ever stored, logged or used for training • Fully anonymised technical logs only (no personal or patient data) • Access limited to authorised hospital and clinic staff • Patients have no access to the system
• HIPAA-compliant environment • GDPR-ready design • Business Associate Agreements (BAA) available for all paid plans • Regular security reviews and penetration testing • Role-based access control and API key management (rotation, enable/disable)
• We never store clinical content after the temporary report is generated • We never train AI models on customer or patient data • We never share clinical data with third parties
If you have specific security questions or require a detailed security questionnaire for your hospital procurement process, please contact us.