Skip to main content

Trust Center

Evidence you can verify, with boundaries you can trust.

This page describes current platform controls. It is not a legal compliance determination for Krasyn or any customer.

No counsel-approved compliance attestation is currently published.

Krasyn will add a legal attestation only after documented counsel approval. Technical evidence below is internally reviewed and expires automatically.

Current platform evidence

Last reviewed 2026-08-27 · Owner: Krasyn Security Engineering

Current technical evidence

Tenant-scoped compliance evidence

Compliance evidence reads and writes derive the organization and actor from the authenticated server context; the form cannot select another tenant.

Owner
Krasyn Security Engineering
Verified
2026-07-30
Expires
2026-10-28
Current technical evidence

Append-only evidence history

New evidence is stored as a new timestamped event with actor identity. The customer workflow does not expose update or delete operations.

Owner
Krasyn Security Engineering
Verified
2026-07-30
Expires
2026-10-28
Current technical evidence

Evidence freshness fails closed

Missing, invalid, expired, or unavailable evidence is shown as Unknown, Error, or Stale and is never counted as current.

Owner
Krasyn Product Security
Verified
2026-07-30
Expires
2026-10-28
Current technical evidence

Text and reasoning AI has one model vendor

Every text and reasoning model call in the product is constructed by a single Azure OpenAI client factory. The codebase holds no client for any other model vendor. This item covers text and reasoning only. Speech-to-text transcription runs on a separate path and is not covered here.

Owner
Krasyn Platform Engineering
Verified
2026-08-27
Expires
2026-11-25
Current technical evidence

No clinical content reaches a training endpoint

Every model call the product makes is a stateless completion, embedding, or transcription request. No code path calls a fine-tuning, training-file, or batch-upload endpoint. This states what our code does. It is not a statement about a model vendor's own retention or abuse-monitoring practices.

Owner
Krasyn Platform Engineering
Verified
2026-08-27
Expires
2026-11-25
Current technical evidence

Note Check reports its own judge status

Every Note Check report carries a judge status: ran, ran on a partial transcript, failed, or not run. Statements the judge did not assess are labelled Unverified, are never counted as Supported, and the report never states a figure its own counts do not support.

Owner
Krasyn Product Engineering
Verified
2026-08-27
Expires
2026-11-25
Current technical evidence

Where visit audio goes, and where it does not

Recorded visit audio is never written to Krasyn database, disk, or object storage. Until a segment uploads it is held in the clinician browser so a crash does not lose the visit, then cleared. Production standalone Scribe uses the Azure Whisper path displayed before recording and does not fall back to browser speech when its provider is unavailable. Other explicitly enabled development or test configurations can use browser speech recognition; that alternative commonly sends audio to the browser vendor and has no Krasyn BAA coverage. It is not the production standalone Scribe recording route. The product states the active backend and that caveat on the recording screen before capture starts, and the same wording is guarded by test.

Owner
Krasyn Security Engineering
Verified
2026-08-27
Expires
2026-11-25
Current technical evidence

Scribe transcripts are destroyed on a stated schedule

The default policy destroys a scribe transcript once the note is approved, with a 90-day backstop for sessions that are never approved. A scheduled sweeper performs a hard delete and redacts verbatim excerpts out of derived records. A practice may instead choose to keep its transcripts until it deletes them. The policy covers the raw transcript of the conversation. The signed note is the medical record and is not touched by it.

Owner
Krasyn Security Engineering
Verified
2026-08-27
Expires
2026-11-25
Current technical evidence

Note Check reports have no automatic expiry

A finished Note Check report is stored inside the practice's own organization scope under a fingerprint of its inputs, which is what makes the same inputs return the same report. There is no automatic expiry and no scheduled deletion for these reports today. We state this because a retention page that goes quiet about one artifact is worse than one that names it.

Owner
Krasyn Security Engineering
Verified
2026-08-27
Expires
2026-11-25
Current technical evidence

A Business Associate Agreement is available in-app

The current Krasyn Business Associate Agreement is presented for review and electronic acceptance by an organization administrator inside the workspace, and the accepted version is recorded. The document was adopted by the owner and has not been reviewed by outside legal counsel.

Owner
Krasyn Security Engineering
Verified
2026-08-27
Expires
2026-11-25

Each item names the file it was read from, the person who owns it, the date it was checked, and the date it stops counting as current. Claims about clinical benefit are governed separately, by the registered protocol described on the Clinical Proof Program page.

Krasyn's responsibility

  • Operate and maintain the platform controls described here.
  • Keep published evidence owned, dated, and current.
  • Show unknown or unavailable states instead of inferred assurance.

Your clinic's responsibility

  • Execute the agreements required for your use.
  • Train your workforce and maintain your own policies and risk assessment.
  • Configure access, review activity, remediate findings, and obtain legal advice for your circumstances.

Clinical AI has a separate release gate

Read how Krasyn measures grounding, critical invention, omission, edit burden, difficult inputs, monitored rollout, and rollback without turning an internal test count into a clinical-benefit claim.

Read AI evaluations