Zero data retention · Zero data collection · Zero patient data
Trust

Security – SHOMA AI Health API

We designed the platform with a zero-trust, zero-retention architecture specifically for healthcare environments.

Core Security Principles

• End-to-end encryption (AES-256) for all data in transit and during processing • Client-side envelope encryption option available • Strict zero data retention: all clinical documents and generated reports are permanently deleted immediately after delivery • No patient data is ever stored, logged or used for training • Fully anonymised technical logs only (no personal or patient data) • Access limited to authorised hospital and clinic staff • Patients have no access to the system

Infrastructure & Compliance

• HIPAA-compliant environment • GDPR-ready design • Business Associate Agreements (BAA) available for all paid plans • Regular security reviews and penetration testing • Role-based access control and API key management (rotation, enable/disable)

What we never do

• We never store clinical content after the temporary report is generated • We never train AI models on customer or patient data • We never share clinical data with third parties

If you have specific security questions or require a detailed security questionnaire for your hospital procurement process, please contact us.