Skip to main content
Hydor Health

Trust Center

TheTrustCenter.

Everything an institutional visitor needs to verify that Hydor can be entrusted with sovereign health infrastructure. Security, privacy, compliance, and responsible AI. Downloadable artifacts where authorization permits. The full governance posture lives at /platform/thia.

Institutional records

AI governance

THIA is the governance framework underneath every Hydor clinical surface. TruthChecker, AutoRAG, the audit trail, the Global Ethics Council, the Clinical Oversight Panels, and the Five Ethics Pillars all live there. The full description, including the governance flow for every output, is published at /platform/thia.

Security

HTTPS only with HSTS preload. TLS 1.3 minimum. Cloudflare web application firewall, bot management, and DDoS protection in front of every public property. Content Security Policy locked. Subresource Integrity on third-party assets. CSRF protection and rate limiting at the edge. Quarterly external penetration tests of every gated form. Quantum-ready cryptographic posture on the roadmap for the platform layer.

Privacy and sovereignty

Data residency is a default. Federated architecture with cross-border exchange under signed receipts. Reversible consent at the patient level. HealthID identity protections that allow verification without record disclosure. No PHI on any public chain, ever.

Compliance

HIPAA-aligned intake at every public touchpoint. Section 508 conformance for federal engagement. WCAG 2.1 AA at launch with a path to 2.2 AA within six months. GDPR and CCPA cookie posture and data subject request workflow. SOC 2 Type II and FedRAMP postures on the roadmap for hosted platform services.

Responsible AI

The Responsible AI policy is published and dated. It includes the model evaluation rubric, the incident disclosure pathway, and the rules of engagement for clinical surfaces. It is reviewed annually and after any material model release. The deep description of how every output is verified is at /platform/thia.

Compliance posture

What we can back today, and what is on the roadmap.

Full color is verifiable now and matches our legal pages. Grayscale is a published path with a named owner, not a claim. Each one is detailed below in the Trust Center.

HIPAA

Aligned

GDPR

Aligned

CCPA / CPRA

Aligned

WCAG 2.1 AA

Conformant

Section 508

Conformant

SOC 2 Type II

On the roadmap

ISO 27001

On the roadmap

Next step

Continue with Hydor Health.