ENTERPRISE TRUST
Security at MedTalk
Security designed for clinical information, from encryption to responsible disclosure.
11
security principles
AES-256
encryption at rest
TLS 1.3
encryption in transit
Security principles
Encryption in transit and at rest
Strong authentication
Role-based access
Tenant isolation
Least privilege
Secure secrets management
Audit logging
Vulnerability management
Secure development
Incident response
Backup and recovery
Implemented controls
AES-256-GCM encryption at rest and TLS 1.3 in transit. ACSC Essential Eight-aligned controls across Australia's primary cybersecurity framework. An IRAP assessment is in progress. Burn-after-read audio destruction removes recordings permanently and irreversibly within 24 hours of capture. NER-based PII de-identification strips identifying information before any data reaches an AI model. Every interaction is captured in a tamper-evident audit log.
Responsible disclosure
Security researchers can report a vulnerability via our monitored security contact, published at /.well-known/security.txt.
ENTERPRISE TRUST CLUSTER
The trust cluster
MORE OF THE SECURITY LAYER
Resilience & engineering
Contact
Security & Compliance: support@medtalk.co
Legal / compliance: legal@medtalk.co