Compliance & security

Aligned with the standards clinicians expect.

Ozana AI is built for regulated clinical environments. This page summarises our compliance posture and the architectural choices behind it.

Standards

HIPAA aligned

Designed to support HIPAA-regulated workflows in the United States.

GDPR aligned

Data minimisation by design - nothing about the encounter is stored at rest.

NHS DTAC aligned

Designed to meet the NHS Digital Technology Assessment Criteria.

ISO 27001

Certification in progress.

End-to-end encryption

Encrypted in transit and in memory; no plaintext audio or transcripts leave the session.

Clinician-verified output

Nothing is filed automatically - a clinician approves every note.

Zero-data-storage architecture

Audio and transcripts are ephemeral. They live only in memory for as long as the pipeline needs them, then they are discarded. No recordings, no stored transcripts, nothing about the encounter at rest. Only the clinician-verified note leaves the session. See the technology page for details.