Encrypted on your device
Patient names, MRN, date of birth and free-text notes are sealed with AES-256-GCM before they leave the device. Each record’s envelope is bound to that record, so it can’t be moved to another.
Patient names, MRN, date of birth and notes are encrypted on your device before they are saved or synced, with a key only your PIN or recovery code opens. The server keeps ciphertext and the coded clinical answers that power the audit, hosted in Frankfurt under the GDPR.
Patient names, MRN, date of birth and free-text notes are sealed with AES-256-GCM before they leave the device. Each record’s envelope is bound to that record, so it can’t be moved to another.
Your key is derived with Argon2id from your PIN and a share the server holds; ten wrong PINs lock it. A recovery code you keep opens it if the PIN is forgotten.
A hospital workspace has its own key, wrapped for each member with their P-256 key pair, and rotated when someone leaves. Members compare key fingerprints before sharing.
Hospital reports are built from coded answers only; counts under 5 are withheld, and every report opened is logged for the hospital’s owners.
The database and API run in Frankfurt (Neon). Data stays in the EU under the GDPR.
Export everything to Excel at any time. "Delete all my data" and "Delete my account" erase it, including the history, and send you a receipt.
| Data | On the server |
|---|---|
| Names, MRN, date of birth, notes | Ciphertext only; the key never leaves your devices unencrypted |
| Clinical answers (eye, dates, biometry, complications, VA) | Stored as entered, to sync and to compute the audit |
| Your PIN | Never; a proof derived with Argon2id is checked instead |
| Hospital reports | Built from coded answers only; counts under 5 withheld; every look logged |
| Post-op checks | A code hash, the eye, the surgery date and the result; no patient identifiers |
Questions about security or a data processing agreement for your hospital:asad@zaions.com.