← OncoSyntra

Security boundary

The public prototype uses synthetic patient data. Implemented controls include SMART PKCE/state handling, server-side token storage contracts, issuer validation, private service ports, trusted-host handling, audit records, provenance, and privacy-controlled population release.

Real PHI deployment additionally requires institutionally approved identity/RBAC, MFA/SSO, encryption/key management, vulnerability management, penetration testing, audit retention, incident response, backup/disaster recovery, and organizational compliance review.