← Aegis Technologies Inc.About

Data and security

What happens to your records.

Our handling of your data in plain terms, limited to what we can stand behind.

  • You send exports. We install nothing and connect to none of your systems.
  • Files come in through a private upload link, not as email attachments.
  • A person inspects each file before any of it is loaded.
  • Processing happens on an encrypted workstation and through our AI provider, Anthropic, which does not train its models on our clients' data.
  • Your data sits in a store of its own, kept apart from every other customer's.
  • We delete it 30 days after the pack is delivered unless you convert to a subscription, or sooner if you ask, and confirm in writing.

What we take, and what we turn away

We take quality records: CAPA, complaints, nonconformances, calibration, training, suppliers, documents, design history, risk files, audit findings and the other registers our templates cover. People appear in them only as names, employee IDs and roles.

We do not take patient-identifiable information. De-identify complaint, adverse-event and MDR records before upload, removing patient names, dates of birth, medical record numbers, addresses and contact details. MedAssure is not built as a HIPAA-covered system. Export-controlled technical data is also excluded, as is personal data other than names, employee IDs and roles. The fit check raises this before any payment. Unsure about a record? Ask us before you upload it.

Should restricted data reach us regardless, we halt, leave it unprocessed, delete it, and send you written confirmation that it is gone.

Where processing happens

Checking and processing take place on an encrypted workstation. For the AI-assisted parts of the analysis, Anthropic processes the data with Claude as our named subprocessor, with model training on our clients' data turned off.

During the beta there is no customer login. The pack reaches you as files at the walk-through call.

Who can see it

Two parties: the person who checks your data and reviews each page of your pack, and Anthropic as processor for the analysis. Nobody else receives it. The Audit Defense Pack Services Agreement carries confidentiality terms, and your records stay your property.

Retention

We delete your data 30 days after the pack is delivered unless you convert to a subscription, and you may ask for deletion at any point before that. That covers the files you uploaded, the store they went into and the reports generated from them, and we confirm it in writing.

What we do not claim

We hold no third-party security certification or attestation at present, such as SOC 2 or ISO 27001. The beta is not set up for patient health information or export-controlled data. MedAssure is not a validated 21 CFR Part 11 system of record; your own QMS keeps that role. If your supplier security review needs something particular, say so on the fit check and you will get a straight answer.

This website

Fit check answers go to our own server so that we can reply. The privacy notice (draft) covers the rest.

Questions on data handling: email us.