Security by design
PBRx's intended architecture treats security as part of the product, not a statement added afterward. Controls must be implemented, tested, monitored, and improved as the platform develops.
Patient-centered access
Access and sharing should follow explicit authorization and the user's selected patient context.
Tenant and identity isolation
Account, patient-profile, and organizational boundaries are designed to remain separate and enforceable.
Backend-controlled AI
Protected information should not be sent directly from a browser to model providers. Eligible services and approved configurations must be enforced through controlled server paths.
Evidence provenance
Source, date, extraction path, confidence, and unresolved conflicts should remain traceable.
Least privilege
People and systems should receive only the access needed for an authorized task.
Defense in depth
Authentication, authorization, encryption, monitoring, logging, vendor controls, secure development, and incident response work together.
Current prototype boundary
PBRx remains in controlled closed beta. Public health-data uploads are not accepted through PBRx.com. Security claims on this page describe the platform's design direction and controls under development; they do not claim an independent certification that has not been identified.
Responsible reporting
A dedicated public security-reporting channel will be published when PBRx's custom-domain contact system is ready. Do not include personal health information in ordinary email.