Legal

Security Policy

Effective 3 August 2026

1. Certifications & compliance

Active certifications: ISO 27001 (information security management) · ISO 13485 (medical device QMS) · GMP · FDA 510(k) K240353 · Korea MFDS.

HIPAA — PurpleAI executes a Business Associate Agreement with every US covered entity, and PHI is processed under the terms of that BAA.

PurpleAI maintains ISO 27001 certification for its information security management system, independently audited and renewed annually. SOC 2 Type II attestation is on the roadmap; ISO 27001 documentation and the security overview are available to customers and partners on request.

2. Data encryption

No persistent clinical data store — DICOM studies are processed in memory and automatically purged 2 hours after receipt. Encryption in transit is applied at commercial deployment: DICOM TLS configured jointly with the institution’s PACS and network teams, or an IPsec site-to-site VPN as an accepted equivalent. On-premise deployments keep all traffic inside the institutional network.

3. Cloud infrastructure

Infrastructure is hosted on Amazon Web ServicesUS region as the default for US healthcare facilities; Korean deployments run in AWS Seoul (ap-northeast-2). Deployment is available cloud or on-premise depending on institutional requirements; on-premise installations keep all data inside the institution’s own network.

4. Access control

Infrastructure access is limited to a single PurpleAI-controlled AWS account with multi-factor authentication enforced. Audit logging via AWS CloudWatch with 90-day retention. The processing service exposes no user-facing interface — DICOM C-STORE/C-ECHO only; no query/retrieve, no bulk export, no API surface.

5. Vulnerability management

Responsible-disclosure inquiries to security@purple-ai.co — live and monitored. Penetration testing: one assessment is planned at first commercial deployment. PurpleAI does not claim testing that has not occurred.

How a study moves
AAt the institution

A non-contrast brain CT is acquired and archived in the institutional PACS. The institution initiates a standard DICOM C-STORE push. Where a use case calls for de-identified data, the sending institution performs that step.

Customer-controlled environment
BIn transit

C-STORE and C-ECHO only — no query/retrieve, no bulk export, no API. Transport security is configured at commercial deployment.

Institution → PurpleAI
CPurpleAI processing

The DICOM SCP receives the series with no user-facing interface. Hemorrhage detection runs in memory and returns a single report DICOM carrying a binary result — suspected or not suspected — with no heat-map imagery in FDA triage mode.

No database · no retained studies · scheduled auto-purge

Return path. The result DICOM is pushed back to the institutional PACS via C-STORE and surfaced in the radiology worklist. No data is transmitted to any third party.

On-premise variant. Installed inside the institution’s own infrastructure, transit and processing sit within the institutional network: no study data crosses the institutional boundary, no PurpleAI-operated cloud account is involved, and network, logging and access controls follow the institution’s own policies.

Security controls by deployment model
ControlCloud — demo / evaluationCloud — commercialOn-premise
Transport encryption (TLS)Not applied — sample studies only; no live patient data.Applied. Configured jointly with the institution’s PACS and network teams, as DICOM TLS requires support at both endpoints. IPsec site-to-site VPN accepted as equivalent.N/A — traffic remains inside the institutional network.
SSH source-IP restrictionNot applied — institution egress addresses are unknown until a deployment is agreed.Applied. Administrative access restricted to a named allow-list built from the institution’s egress addresses.N/A — no PurpleAI-operated infrastructure exposed.
AWS account MFAEnforced.Enforced on the AWS account administering the deployment.N/A — no PurpleAI cloud account.

Commercial is the point at which the system begins processing live patient studies. Where an evaluation or pilot involves live clinical data, commercial-stage controls apply at that point — not at contract execution.