CURAELLE

Trust by design

Security overview

How CURAELLE handles identity, authorization, isolation, audit and human-governed intelligence today. This page describes an evaluation environment that holds synthetic data only. It is a factual overview, not a certification.

Identity and access

  • Sign-in is Google OpenID Connect, performed by the server. CURAELLE stores no passwords.
  • There is no public sign-up. Only provisioned accounts can enter a product.
  • An account moves through a controlled lifecycle: pending, approved, active, suspended, revoked.
  • A Google identity that CURAELLE has not authorized is refused and shown no product data.

Authorization and isolation

  • Every operation is authorized on the server. Product, edition, tenant and jurisdiction scope are never taken from the browser.
  • Tenant isolation is enforced in the database with forced row-level security.
  • Each product has its own database. No product reads another product’s database.
  • Hospital Private Edition and Public Edition run as separate processes with separate data.

Sessions

  • Sessions are held on the server, not in the browser.
  • A session ends after 30 minutes without activity and after 12 hours in any case.
  • Changing another person’s access requires a fresh Google re-authentication, no older than five minutes. The elevation then lasts 15 minutes.
  • The primary owner account is protected by the service and by database constraints.

Audit and evidence

  • Each product writes an audit record on the operation path.
  • A refusal is recorded as well as a success, so an attempt stays visible.
  • A request can be followed end to end by its correlation identifier.

Human-governed intelligence

  • AI produces a draft. A named person reviews it and accepts, edits or rejects it.
  • Only approved output can act, and each step is audited.
  • Diagnosis, prescribing, triage and clinical clearance are refused categorically.
  • No AI model provider is connected in this environment.

This website

  • Static pages served from one origin. No cookies, no analytics, no third-party requests and no forms.
  • The contact actions are email links; nothing is submitted through the site.
  • The web server keeps standard access logs.
  • Search indexing is disabled while the environment is under evaluation.

Capability is not connection

CURAELLE separates what the platform can do from what a deployment has switched on. The integration surfaces exist; providers are selected, credentialed, connected and certified per deployment. In this environment every provider family stands as follows.

Provider familyCapability availableProvider selectedConnectedLive certified
AIYesNoNoNo
MessagingYesNoNoNo
PaymentYesNoNoNo
FHIRYesNoNoNo
HL7 v2YesNoNoNo
DICOMYesNoNoNo
Health information exchangeYesNoNoNo

Google sign-in is the one live external dependency.

Transport and browser protections

  • HTTPS only, with HTTP Strict Transport Security for one year including subdomains.
  • A Content Security Policy that allows scripts from the site’s own origin only.
  • Framing is denied, content-type sniffing is disabled, and camera, microphone, geolocation and payment browser features are switched off.
  • Runtime metrics are not exposed through the public edge.

What this page does not claim

  • No third-party security certification or attestation.
  • No production deployment and no customer deployment.
  • No real patient data: the environment holds synthetic data only.
  • No published privacy policy or terms of service yet. Backup, disaster recovery, residency and monitoring obligations are defined per deployment.

Questions and reports

For a security question or to report a concern, write to hello@curaelle.com.