How we handle data.
Principles
We don’t collect what we don’t need. This website receives no medical images and no patient data.
Research imaging is never handled through public infrastructure. It moves only under a written agreement, into environments provisioned for it.
Where imaging is shared with us for research, we work with de-identified data wherever possible, and DICOM metadata is stripped of identifiers before analysis.
Our pipeline is built around provenance: outputs record the method and version that produced them. The same audit-mindedness governs how data moves.
Practical measures
- Encryption in transit (TLS) for the website and any data exchange
- Access limited to those who need it, with individual accounts
- Separation between public website infrastructure and any research environment
- Written data-processing agreements before any imaging is received
Certifications
We do not currently hold ISO 27001 or SOC 2 certification. We build to their principles and will pursue certification as we move toward commercial deployment.
Reporting a vulnerability
If you believe you’ve found a security issue, please tell us at anamaria.chioran@corpxanalytics.com. We’ll acknowledge your report and keep you updated. Please give us reasonable time to fix an issue before disclosing it publicly.
Related
CorpX software is Research Use Only. How we treat personal data on this site is set out in our Privacy notice.
Questions
Security reviews and vendor questionnaires: anamaria.chioran@corpxanalytics.com