Skip to content

Security and compliance at the core

SentinelMind is built from the ground up with Danish healthcare law and GDPR in mind.

GDPR compliance

Full support for data subject rights: access, export, and deletion. All requests are logged and processed systematically.

Consent-based data processing

No patient data is processed without explicit, informed consent. Consent can be withdrawn at any time.

Immutable audit log

All access to patient data — views, lists, timeseries — is logged with actor, clinic, patient ID, and correlation ID.

Encryption

Sensitive data is encrypted with AES-GCM locally on the patient's device. All communication happens over TLS.

Data retention

Audit logs are retained for 365 days. Completed jobs are cleared after 30 days. Failed jobs after 90 days.

PII filtering

Analytics data is automatically filtered for personally identifiable information before storage.

Rate limiting

All endpoints are protected with rate limiting to prevent abuse.