Safety & privacy
We earn your trust with specifics — not platitudes.
Below are the things we name: the encryption, the retention window, the export format, the providers we use, and the gap we're honest about (no HIPAA, yet).
Six principles
How Medical Records Vault talks about your health.
We never diagnose.
Medical Records Vault explains what was used and why it is commonly used. We will never assert what you definitely had — that's your doctor's job, with information we don't have.
We always hedge.
Every explanation uses careful language: "likely used for", "commonly given when". Never "you definitely had". Hedging isn’t a hedge — it’s honesty about what an AI reading paperwork can and cannot know.
We always caveat.
Every report and every chat answer carries a clear disclaimer. You'll know, every time, that you're reading an educational explanation — not medical advice.
We never accuse.
If a standard protocol item appears to be missing, we say "ask your doctor about the reasoning". We never say "your doctor failed". Clinicians make judgement calls that our extractor cannot see.
We always recommend a doctor.
For any clinical decision — changing a medication, interpreting a flagged value, deciding what to do about a trend — Medical Records Vault points you back to your doctor. Always.
We're transparent about confidence.
Low-confidence extractions are flagged in the UI and surfaced as questions to ask your doctor. We'd rather tell you we're unsure than pretend otherwise.
Privacy by design
The specifics — the things most apps won't put on their site.
Encryption
Encrypted at rest using EBS volume encryption with a KMS-managed key. Encrypted in transit over TLS 1.2+ end-to-end.
Never used to train models
Your documents and chat history are never used to train any AI model — ours or our providers'. We use OpenAI and Anthropic with no-training settings on every request.
PII scrubbed from logs
Our application logs strip personal identifiers before they're written. Operational telemetry never contains your records.
Soft-delete with restore
Deleted documents go to trash for 30 days with a visible days-remaining countdown. Restore them with one click. After 30 days, they're hard-deleted.
ZIP export, no friction
Export every original file, every AI analysis, and every chat transcript as a single ZIP. One click, no upgrade required, no support ticket.
Hard-delete on request
Email contact@fourtwos.com to permanently delete your account and all associated data. We process within 30 days.
Per-user cost cap
Each account has a daily LLM spend cap so the product can't be weaponised — yours or someone else's — to run up a bill.
Dual-provider redundancy
Medical Records Vault uses both OpenAI and Anthropic. If one provider has an outage, your chats keep working.
Compliance
Where Medical Records Vault stands today — and where it doesn't.
We'd rather be explicit about the gap than hide behind language that sounds reassuring.
GDPR-aligned
EU users have rights to access, rectification, portability, erasure, and objection. The ZIP export covers portability; email contact@fourtwos.com for the others.
India DPDP-aligned
Medical Records Vault is built to meet the requirements of India's Digital Personal Data Protection Act, including consent-based processing and breach notification.
Not HIPAA-compliant
Medical Records Vault is not HIPAA-compliant and is not intended for use in US clinical settings. We do not have a Business Associate Agreement (BAA) in place with OpenAI or Anthropic. If you are a US clinician or a US-regulated entity, please do not upload patient PHI.
Not a medical device
Medical Records Vault is an educational tool. It is not a medical device under FDA, CE, or CDSCO classification. Nothing here — ever — should be treated as medical advice or diagnosis.
Reach the right team directly.
One address for security, privacy, and abuse — and we read every email ourselves.
Security, privacy, abuse & help
contact@fourtwos.com