Data protection
Designed for clinical data from the first line of code
Clinical notes contain some of the most sensitive information in existence. CliniNote was built with that in mind, not retrofitted for compliance after the fact.
Data handling
Your data does not train our models. Full stop.
When you upload clinical notes to CliniNote, those notes are used for one purpose: running the extraction job you requested. They are not stored beyond your configured retention period. They are not used to improve or retrain the extraction models. They are not shared with any third party or analyzed for any purpose other than the job you submitted.
Uploaded documents are encrypted at rest using AES-256 immediately on receipt. Data is processed in isolated job environments that do not share memory space or storage with other customers. Processing outputs are written to your organization's dedicated storage partition, also encrypted at rest.
Transmission between your system and the CliniNote API uses TLS 1.3. Connections using older protocol versions are rejected at the load balancer.
Data residency
EU-West by default. US region available.
CliniNote processes data in the region you select at account creation. The default region for new accounts is EU-West (Frankfurt). US-East (Virginia) is available for US-based organizations with specific data residency requirements.
Data does not cross regional boundaries during processing. If you need to change your data residency region, contact support before uploading any data, as migration requires a fresh account provisioning.
For organizations operating in multiple jurisdictions, reach out to discuss a dedicated instance arrangement with custom network topology.
Access controls
Role-based access that mirrors how clinical research teams actually work
Not every team member needs the same level of access. CliniNote's permission model supports the separation your IRB and data governance policies require.
-
Role-based permissions
Roles include Admin, Analyst, Reviewer, and API-only. Admins manage users and billing. Analysts run jobs and export results. Reviewers access outputs read-only. API-only accounts are service accounts with restricted surface area.
-
Project-level isolation
Jobs and outputs are organized into projects. Access can be restricted to specific projects, so a team working on Study A has no visibility into Study B, even within the same organization account.
-
MFA enforcement
Multi-factor authentication can be enforced at the organization level. Admins can require MFA for all team members before any job can be submitted. TOTP and hardware security keys are both supported.
-
API key rotation
API keys are scoped to specific permissions and can be rotated on demand from the admin console. Key usage is logged with IP, timestamp, and resource. Compromised keys can be revoked without disrupting other active keys.
-
Audit log export
All access events, job submissions, export actions, and admin changes are recorded in a tamper-evident audit log. Logs can be exported to your SIEM or compliance system via a dedicated read-only API endpoint.
-
SSO integration
SAML 2.0 and OIDC integration is available on the Institution plan. Connect to your existing identity provider so CliniNote access is governed by the same policies as your other institutional systems.
Compliance posture
HIPAA, GDPR, and the agreements your legal team will ask about
CliniNote is designed to support HIPAA-covered entity workflows. A Business Associate Agreement is available as a standard offering for all Research and Institution plan customers. The BAA is included in your contract and does not require a separate negotiation process.
Processing in EU-West is designed to comply with GDPR Article 28 requirements for data processor agreements. A Data Processing Agreement is available alongside the BAA for organizations operating under EU data protection rules.
Penetration testing is conducted annually by an independent security firm. Infrastructure is hosted on cloud providers that maintain SOC 2 Type II certification. Our own SOC 2 audit is in progress; if you have a specific compliance timeline, contact us to discuss your requirements.
De-identification and IRB
Built for de-identified data. Documented for IRB review.
CliniNote processes de-identified clinical notes per HIPAA Safe Harbor or Expert Determination standards, depending on the de-identification approach your organization uses. The platform does not require PHI to function, and we recommend running de-identification before upload as a second layer of protection.
For organizations that need to submit CliniNote as a described tool in an IRB protocol, we provide a technical description document that can be incorporated into your Data Use section. Contact your account manager or reach out through the contact form to request the document.
Outputs are structured datasets of extracted clinical concepts, not reproduced note content. Extracted entities reference source positions for validation purposes but do not reconstruct original text in the output files.
Review the full security documentation
Request early access and receive our security and compliance documentation package, including BAA template, data flow diagrams, and infrastructure overview.