Security & Compliance

Your data, our posture

MedGuard processes the inputs you submit for analysis. This page states, plainly, what we handle and what we do not claim.

What we handle

health-AI tool descriptions, use cases, and user-type selections for safety screening.

Data handling commitments

  • Submissions run the product pipeline and are retained only as long as needed for your audit log (paid tiers) or until you delete the run.
  • We apply access controls consistent with GDPR Art. 32 (security of processing) where personal data is processed.
  • BYOK keys (Enterprise), when offered, are stored server-side only and never exposed to the browser.
Honesty rule: MedGuard flags safety and evidence concerns for health-AI tools. It is not a medical device, not clinical advice, and does not guarantee patient safety, 100% detection of unsafe advice, or that you will never miss a risk. We do not claim guarantee / 100% / never miss.

Our compliance posture

  • MedGuard is decision-support, not a law firm, clinic, or certified auditor.
  • For binding advice, consult a qualified professional in the relevant domain.

Subprocessors & payments

  • Payments are processed by Waffo Pancake (merchant of record).
  • See Privacy and Terms for full terms.

refs: FDA AI/ML medical devices overview · FTC health claims guidance · EU AI Act (health-related high-risk context)