Skip to content

Trust & safety

Clinical AI that is accountable by design

Trust is earned through clear roles, visible reasoning and a complete record. These principles shape every part of the platform.

Principles

Four commitments we don't compromise on

  • Physicians decide

    The software offers decision support only. Every finding is accepted, edited or overridden by a qualified clinician, and only a clinician can sign a report.

  • Transparent reasoning

    When the second reader raises a flag it shows its work: the region, the overlays and a plain-language explanation, so the reader can judge it on its merits.

  • Full audit trail

    Reads, flags, decisions and rationales are recorded in an append-only log that supports clinical governance and quality review.

  • Privacy by design

    Data handling is designed around minimisation, access control and encryption, and is configured to meet each partner lab's own policies and obligations.

Audit trail

A complete, attributable record

Every read, flag, decision and rationale is recorded in order and attributed to a person or system — supporting governance, peer review and incident investigation.

Audit trail
  1. Study received

    09:02 · System

    Routed from PACS to the reading worklist

  2. Radiologist read submitted

    09:15 · Radiologist

    Initial impression recorded before any AI output was shown

  3. Second reader analysis completed

    09:15 · Second reader

    Independent analysis of the same study

  4. Disagreement flagged

    09:16 · Second reader

    Reasoning, overlays and region references attached

  5. Radiologist decision

    09:21 · Radiologist

    Flag reviewed; decision and written rationale captured

  6. Report signed

    09:24 · Radiologist

    Final report signed by the radiologist

Each record is append-only and attributable.

Illustrative example — not real patient data.

Practices

How the principles show up in practice

  • Human oversight

    The workflow requires a clinician's decision for every flag and every report. The AI has no path to act on its own.

  • Known limitations

    We document what the second reader is and isn't intended for, and share those limits with readers during onboarding.

  • Monitoring

    Override patterns and feedback are reviewed with partner labs to understand real-world behaviour over time.

  • Access control

    Role-based access, least-privilege defaults and attributable actions throughout the platform.

  • Data protection

    Designed for encryption in transit and at rest, data minimisation, and retention configured to each partner's policies.

  • Regulatory awareness

    Product availability and intended use depend on the regulatory status in each market. We discuss this openly with every partner.

Our language

How we describe what the AI does

Words matter in clinical settings. We describe the AI as a second reader that provides decision support. It raises findings for a physician's consideration; the physician interprets them and makes every clinical decision.

FAQ

Trust & safety questions

Does the AI ever communicate directly with patients?

No. Second-reader output goes to radiologists and genomics reports go to reviewing physicians. Nothing is released to patients without clinician approval.

What certifications do you hold?

We only publish certifications and regulatory clearances once they are granted and verifiable. Ask us about current status for your market during a demo.

How do you handle model errors?

The workflow assumes the AI can be wrong. Flags are presented as prompts for review, overrides are expected, and patterns in overrides are reviewed with partner labs.

Bring your governance questions

We welcome detailed questions from clinical governance, information security and procurement teams.