Security and deployment

Current operating boundaries.

Security, privacy, and deployment controls depend on the model, data path, customer environment, and engagement agreement. This page states the current public boundary without implying certifications or deployment modes that have not been established.

Public website boundary

  • The public website and interactive examples use synthetic product illustrations, not patient records.
  • Public contact paths use email links rather than a patient-data intake form.
  • Do not send PHI, patient files, raw governed data, model credentials, private checkpoints, or held-out evaluation rows through public email.

Engagement boundary

  • Model and data access is scoped with the customer before technical work begins.
  • A customer-controlled held-out evaluation path is required for a hardening claim.
  • Institution-local evaluation remains an enterprise design-partner path, not a generally available deployment.
  • The intended local reporting boundary is aggregate evaluation output rather than patient-level exports; the exact implementation must be reviewed for each engagement.

Artifact integrity and separation.

Synset's current software can record versions, manifests, hashes, and release decisions for generated artifacts. A hash can show that a file has not changed; it does not establish clinical validity or model improvement.

  • versioned model, data, scenario, and protocol references
  • stable manifests and artifact hashes
  • release records for accepted synthetic material
  • separation of model-facing prompts from private answer keys
  • explicit public and private evidence classifications
Not currently claimed

Controls require engagement-specific verification.

HIPAA compliance certification
SOC 2 or HITRUST certification
a universally available customer VPC or institution-local deployment
an air-gapped or network-disabled operating mode
standard retention or deletion terms for all engagements
a blanket statement that Synset never receives or stores PHI

Encryption, logging, retention, deletion, network access, ownership, and incident terms must be documented for the specific deployment before governed data is used.

Start a security review before sharing governed data.

Use high-level, non-PHI context in the first message. The approved access and handling path should be established before technical materials are exchanged.