LUMEN
EN FR ع

Compliance

We claim no certificate we do not hold.

This page exists to be checked. It states what is held, what is mapped, and what is only planned, and it never lets those three become one sentence.

Scroll
Compliance
Compliance
01

What we hold today.

Nothing. No certification, no registration, no clearance, no accreditation, in any jurisdiction. Not ISO, not SOC 2, not a medical device clearance, not an SFDA registration.

A pre-revenue company with no manufactured unit and no deployment holds none of those, and any page implying otherwise would be false.

02

What mapped means here.

The architecture is mapped against the frameworks below, meaning each requirement has a named place in the design and a named owner. Mapping is design work. It is not an audit, it is not a certificate, and it never becomes one by being written down.

  • Saudi PDPL, for a deployment in the Kingdom
  • PIPEDA and Quebec Law 25, for Canada
  • HIPAA, for a United States deployment
  • GDPR, for the European Union
  • IEC 60601, which the bedside terminal is designed to support
03

Certification is pursued per deployment.

A hospital's regulatory frame is set by its jurisdiction and by what it does with the system. Certification is therefore pursued for a given deployment, against that hospital's frame, and it is scoped and funded as part of that deployment rather than claimed in advance.

04

The first funded hire is the one that owns this.

The clinical safety, regulatory and quality function is the first hire funded by a first cheque, before any pilot is signed. Until that person exists, no pilot conversation advances past an introduction. That sequence is published on the investors page and it is a commitment, not an aspiration.

05

Medical device posture, stated carefully.

As designed, the system carries clinical communication and drafts text that a clinician signs. Whether a given configuration is a regulated device is determined by jurisdiction and by the claims made for it, and that determination is part of the deployment work above.

The invariant that governs the design is published on the security page: the model never decides alone, and every clinical decision rises to a human signature.

06

Data protection, as built rather than as promised.

Speech is transcribed and redacted on the bedside device before anything is transmitted. The audit chain is append-only and belongs to the hospital. Keys are issued by the hospital and revocable by the hospital. These are architectural properties, and the pages that describe them say plainly that no unit has been built yet.

07

Security contact and disclosure.

If you find a weakness in any of this, write to the founder and a person will answer you. The security architecture is set out in full on the security page.

08

How to check any of this.

Every claim on this site is attached to its source: a published study with its identifier, a measurement with its method and hardware, or a design target with the specification it was computed from. If a sentence anywhere fails that test, write and it will be corrected, and the press page carries a standing corrections note.

Version 2026.08 · Reviewed against the commitments published on the trust page