TRUST & GOVERNANCE

Security isn't a feature.
It's the architecture.

Healthcare-grade trust by design. Every layer of Symphonix is built to protect patient data, enforce compliance boundaries, and provide cryptographic proof of every action taken.

Schedule a Strategy Session
13
Admission Checks
9
Policy Rules
3-Layer
Patient Data Detection
0
Patient Data in Registry
PATIENT DATA ARCHITECTURE

Patient data never leaves the premises.

Symphonix enforces a strict separation between clinical intelligence and patient data. The architecture guarantees that identifiable health information stays within your infrastructure boundaries.

Bevan LLM — Local Execution

Bevan, the embedded clinical language model, runs entirely within your deployment boundary. No patient data is transmitted to external model providers. Clinical reasoning happens where the data lives.

Model Router Classification

Every request is classified by the model router before dispatch. Requests containing patient-identifiable information are routed exclusively to local models. External models receive only de-identified, structural, or administrative queries.

Global Agent Registry Isolation

The GHARRA Global Agent Registry stores capability metadata, trust attestations, and delegation policies. It never stores, transits, or caches patient data. Registry operations are structurally incapable of carrying clinical content.

Three-Layer Detection Pipeline

A three-layer detection pipeline inspects every outbound payload at the edge. Pattern matching, NER-based entity detection, and structural analysis block patient data before it can leave the perimeter. Defence in depth, not single-point filtering.

COMPLIANCE FRAMEWORK

Designed for the strictest regulatory environments.

Symphonix does not claim certifications it has not earned. Each framework below describes the specific alignment, design decisions, and controls implemented.

REGULATION

HIPAA

Administrative, physical, and technical safeguards. Access controls, audit logging, encryption at rest and in transit, minimum necessary access enforcement, and breach notification procedures.

DESIGNED FOR COMPLIANCE
REGULATION

GDPR

Data residency enforcement per jurisdiction. Consent management with granular purpose limitation. Articles 44–49 cross-border adequacy controls. Right to erasure and data portability built into the data layer.

DESIGNED FOR COMPLIANCE
FRAMEWORK

HITRUST CSF

Security framework alignment across control categories. Risk-based approach to information protection. Mapped controls for access management, data protection, and incident response.

FRAMEWORK ALIGNED
REGULATION

EU AI Act

Risk classification alignment for clinical AI systems. Transparency obligations for AI-assisted clinical decisions. Human oversight requirements and algorithmic accountability logging.

RISK CLASSIFICATION ALIGNED
NIST

SP 800-207 — Zero Trust

Zero Trust Architecture principles implemented across all service boundaries. No implicit trust based on network location. Every request authenticated, authorised, and encrypted regardless of origin.

ARCHITECTURE IMPLEMENTED
NIST

SP 800-162 — ABAC

Attribute-Based Access Control for fine-grained authorisation. Policy decisions based on subject attributes, resource attributes, environmental conditions, and clinical context.

ARCHITECTURE IMPLEMENTED
IHE PROFILE

ATNA

Audit Trail and Node Authentication profile. Structured audit event logging conforming to IHE specifications. Secure node authentication for all system-to-system communication.

PROFILE IMPLEMENTED
IETF STANDARD

RFC 8705 — OAuth mTLS

Mutual TLS certificate-bound access tokens. Client authentication via X.509 certificates. Token binding prevents bearer token theft and replay attacks across service boundaries.

PROTOCOL IMPLEMENTED
IETF STANDARD

RFC 9449 — DPoP

Demonstration of Proof-of-Possession token binding. Cryptographic proof that the presenter of a token is the legitimate holder. Mitigates token exfiltration and man-in-the-middle scenarios.

PROTOCOL IMPLEMENTED
ZERO-TRUST ARCHITECTURE

Never trust. Always verify.

Every request entering Symphonix is treated as untrusted regardless of network origin. Authentication, authorisation, and integrity verification occur on every call, every time.

Authentication & Token Security

  • Every request authenticated with JWT tokens signed using RS256, ES256, or EdDSA algorithms
  • Mutual TLS (mTLS) certificate-bound tokens per RFC 8705 — tokens are cryptographically tied to the presenting client certificate
  • Demonstration of Proof-of-Possession (DPoP) per RFC 9449 — each token use requires a fresh cryptographic proof
  • No bearer tokens in production — every token is bound to its holder through at least one proof-of-possession mechanism
  • Token lifetime enforcement with automatic rotation and revocation propagation across the service mesh
  • 13-point route admission validation on every agent-to-agent delegation request

Service Mesh Security

All inter-service communication encrypted with mTLS. Service identity verified on every request. No plaintext communication between any components, including internal services. Network segmentation enforced at the infrastructure layer.

Attribute-Based Access Control

Authorisation decisions based on subject role, department, clinical context, resource sensitivity, time constraints, and jurisdictional rules. Nine policy rules evaluated on every access decision. Deny-by-default with explicit grant required.

TRANSPARENCY & AUDIT

Cryptographic proof of every action.

Every mutation, delegation, and clinical decision in Symphonix is recorded in an append-only, hash-chained transparency ledger. Audit trails are tamper-evident by construction.

Hash-Chained Transparency Ledger

Every entry in the transparency ledger includes a SHA-256 hash of the previous entry. Tampering with any record invalidates the chain from that point forward. Independent verification possible without access to the underlying data.

Signed Delegation Assertions

When one agent delegates a task to another, the delegation is recorded as a signed assertion. The delegating agent, receiving agent, scope, constraints, and timestamp are cryptographically bound. Delegation chains are fully traceable.

Append-Only Audit Logs

Audit logs are structurally append-only. No record can be modified or deleted after creation. Every clinical action, access decision, and system event is permanently recorded with full context.

SHA-256 Linked Mutations

Every data mutation — create, update, status change — is SHA-256 linked to its predecessor. The complete history of any resource can be independently reconstructed and verified from the hash chain.

EMERGENCY BREAK-GLASS

Healthcare safety is the absolute constraint.

In clinical emergencies, access to critical systems cannot be blocked. Symphonix enforces this as an architectural invariant, not a configuration option.

Emergency Invocations Are Never Blocked

When a clinician triggers an emergency break-glass invocation, the system guarantees execution. Policy engine rules do not block it. Billing constraints do not block it. Jurisdictional boundaries do not block it. This is the absolute healthcare safety constraint — patient care takes precedence over every other system concern.

INVARIANT: Emergency clinical invocations execute unconditionally.
AUDIT: Every break-glass event is logged to the transparency ledger with full context, clinician identity, and justification.
REVIEW: Post-hoc review is mandatory. Access is never denied; accountability is never waived.

See the security architecture in action

Cross-Border Orchestration Demo Agent Network Topology Demo
DATA RESIDENCY

Data residency by design.

Each sovereign BulletTrain instance keeps patient data within national boundaries. Only orchestration signals — never clinical data — cross borders. The Global Agent Registry provides discovery and trust without storing or transiting any patient information.

COUNTRY A BulletTrain Patient data stays here DATA SOVEREIGN COUNTRY B BulletTrain Patient data stays here DATA SOVEREIGN COUNTRY C BulletTrain Patient data stays here DATA SOVEREIGN - - - Orchestration only Patient data stays local
RESOURCES

Download our Trust & Governance Summary

This document outlines our security architecture, compliance alignment, and data protection model.

Book a 30-Minute Architecture Walkthrough

Request a Security Review

Our security team will walk through the architecture, controls, and compliance posture in detail. Bring your CISO.

Request Security Review Security Documentation

HIPAA designed • GDPR enforced • HITRUST aligned • Zero Trust implemented • No patient data in this form