Closed beta · Controlled prototype environment

Trust should be a system requirement.

PBRx is designed around controlled data flows, patient-centered permissions, evidence lineage, separated account boundaries, and human oversight.

Patient controlLeast privilegeEvidence lineage

Security by design

PBRx's intended architecture treats security as part of the product, not a statement added afterward. Controls must be implemented, tested, monitored, and improved as the platform develops.

Patient-centered access

Access and sharing should follow explicit authorization and the user's selected patient context.

Tenant and identity isolation

Account, patient-profile, and organizational boundaries are designed to remain separate and enforceable.

Backend-controlled AI

Protected information should not be sent directly from a browser to model providers. Eligible services and approved configurations must be enforced through controlled server paths.

Evidence provenance

Source, date, extraction path, confidence, and unresolved conflicts should remain traceable.

Least privilege

People and systems should receive only the access needed for an authorized task.

Defense in depth

Authentication, authorization, encryption, monitoring, logging, vendor controls, secure development, and incident response work together.

Current prototype boundary

PBRx remains in controlled closed beta. Public health-data uploads are not accepted through PBRx.com. Security claims on this page describe the platform's design direction and controls under development; they do not claim an independent certification that has not been identified.

Secure business email

PBRx uses Proton Mail for business email under an executed Business Associate Agreement. Proton’s encrypted services support appropriately configured handling of protected health information, but the agreement applies only to covered Proton services and does not extend to the public website, Netlify services, or unrelated systems.

Messages within Proton are encrypted automatically. Messages to outside email providers are not automatically end-to-end encrypted unless additional protection, such as Proton password-protected email, is used. PBRx therefore does not treat ordinary email as a secure patient-submission channel.

Responsible reporting

A dedicated public security-reporting channel will be published when PBRx's custom-domain contact system is ready. Do not include personal health information in ordinary email.