Security and compliance at the core
SentinelMind is built from the ground up with Danish healthcare law and GDPR in mind.
GDPR compliance
Full support for data subject rights: access, export, and deletion. All requests are logged and processed systematically.
Consent-based data processing
No patient data is processed without explicit, informed consent. Consent can be withdrawn at any time.
Immutable audit log
All access to patient data — views, lists, timeseries — is logged with actor, clinic, patient ID, and correlation ID.
Encryption
Sensitive data is encrypted with AES-GCM locally on the patient's device. All communication happens over TLS.
Data retention
Audit logs are retained for 365 days. Completed jobs are cleared after 30 days. Failed jobs after 90 days.
PII filtering
Analytics data is automatically filtered for personally identifiable information before storage.
Rate limiting
All endpoints are protected with rate limiting to prevent abuse.