Skip to content
moirai
Product
Pricing
Buyers
Follow-up previewSynthetic follow-up evidence loopSecurityPrivacy and control posturePublic verifierHash-only evidence lookup
Research
Demo
Take the tour15-minute compatibility loopInteractive demoFollow-up status walkthroughBlogEvidence and operations notes
About
Sign inVerifyPreview
Menu
ProductPricing
Buyers
OverviewFollow-up previewSecurityPublic verifier
Research
Demo
OverviewTake the tourInteractive demoBlog
About
Sign inPreviewOpen Follow-up Preview
placeholder
  • Route20.0 kB
  • First-load190 kB
  • StatusBudget
Public ledger · Live
12 most recent records · click to verifyVerify a hash →
f60d…6495CXR-2026-0847
f60de9172ecabc80520a858d55dfbed0e2b81592e14e977747adba47ec416495
caseCXR-2026-0847toolAnnalise CXRsealed2026-05-07 04:03:00Z · 1h agoprevGENESIS
Click to verify →
0ee5…d64bBCT-2026-0848
0ee5c76a771351aeb9f5789dca3cae2ea0d17b927bccf4234c543667998ed64b
caseBCT-2026-0848toolAidoc PE Detectionsealed2026-05-07 04:12:00Z · 1h agoprevf60de9…416495
Click to verify →
8d13…8a63MMG-2026-0849
8d13c08f55491bceb02cfa16c2ab998182e7c8cc0430d353d50d33be1c238a63
caseMMG-2026-0849toolLunit INSIGHTsealed2026-05-07 04:24:00Z · 1h agoprev0ee5c7…8ed64b
Click to verify →
26dc…0b39BCT-2026-0850
26dca762f427713a5a07bb7a007d140efd6c2b707840f9518a37b664e39a0b39
caseBCT-2026-0850toolHarrison CT Brainsealed2026-05-07 04:31:00Z · 1h agoprev8d13c0…238a63
Click to verify →
c46d…c0f1MRI-2026-0851
c46d98269a4511d23796f04dda7bb4c23097f4d30fb38975ad3fd15bb587c0f1
caseMRI-2026-0851toolBehold MRI Spinesealed2026-05-07 04:35:00Z · 1h agoprev26dca7…9a0b39
Click to verify →
ff8b…6ff8CXR-2026-0852
ff8b19d90abe87a193139a04ea3e2f8dd63c952ad7a71ba6aeabf82fe4606ff8
caseCXR-2026-0852toolAnnalise CXRsealed2026-05-07 04:53:00Z · 47m agoprevc46d98…87c0f1
Click to verify →
fcf0…e6dfCXR-2026-0853
fcf0d27e31534501679a76f801e9291abd85149ffdc999941194a3c93855e6df
caseCXR-2026-0853toolEnlitic Curiesealed2026-05-07 05:04:00Z · 36m agoprevff8b19…606ff8
Click to verify →
febb…06bfBCT-2026-0854
febba551c829cb79d994e89ad476d1f9c7772d7d79cb1e315bab55d7132406bf
caseBCT-2026-0854toolAidoc PE Detectionsealed2026-05-07 05:10:00Z · 30m agoprevfcf0d2…55e6df
Click to verify →
da0c…0f60MMG-2026-0855
da0c4d1526765c82512b24518182cea1d286d3ca170d6115dedc0cc2b7c80f60
caseMMG-2026-0855toolLunit INSIGHTsealed2026-05-07 05:13:00Z · 27m agoprevfebba5…2406bf
Click to verify →
e5e1…a25aMRI-2026-0856
e5e1bce89de66f165094659458f7fb6754f25deaf6ad5bede7ca75a586aea25a
caseMRI-2026-0856toolBehold MRI Kneesealed2026-05-07 05:27:00Z · 13m agoprevda0c4d…c80f60
Click to verify →
6614…b55aBCT-2026-0857
6614270dbc4b3897b06f125b16af3269ecaf29183809961e53803c1bd46db55a
caseBCT-2026-0857toolHarrison CT Brainsealed2026-05-07 05:35:00Z · 5m agopreve5e1bc…aea25a
Click to verify →
2a97…ffe3CXR-2026-0858
2a971540cfd15abf745fd77c58b214a45ef5af5788f861d81ca7549930b5ffe3
caseCXR-2026-0858toolAnnalise CXRsealed2026-05-07 05:40:00Z · 0s agoprev661427…6db55a
Click to verify →
f60d…6495CXR-2026-0847
f60de9172ecabc80520a858d55dfbed0e2b81592e14e977747adba47ec416495
caseCXR-2026-0847toolAnnalise CXRsealed2026-05-07 04:03:00Z · 1h agoprevGENESIS
Click to verify →
0ee5…d64bBCT-2026-0848
0ee5c76a771351aeb9f5789dca3cae2ea0d17b927bccf4234c543667998ed64b
caseBCT-2026-0848toolAidoc PE Detectionsealed2026-05-07 04:12:00Z · 1h agoprevf60de9…416495
Click to verify →
8d13…8a63MMG-2026-0849
8d13c08f55491bceb02cfa16c2ab998182e7c8cc0430d353d50d33be1c238a63
caseMMG-2026-0849toolLunit INSIGHTsealed2026-05-07 04:24:00Z · 1h agoprev0ee5c7…8ed64b
Click to verify →
26dc…0b39BCT-2026-0850
26dca762f427713a5a07bb7a007d140efd6c2b707840f9518a37b664e39a0b39
caseBCT-2026-0850toolHarrison CT Brainsealed2026-05-07 04:31:00Z · 1h agoprev8d13c0…238a63
Click to verify →
c46d…c0f1MRI-2026-0851
c46d98269a4511d23796f04dda7bb4c23097f4d30fb38975ad3fd15bb587c0f1
caseMRI-2026-0851toolBehold MRI Spinesealed2026-05-07 04:35:00Z · 1h agoprev26dca7…9a0b39
Click to verify →
ff8b…6ff8CXR-2026-0852
ff8b19d90abe87a193139a04ea3e2f8dd63c952ad7a71ba6aeabf82fe4606ff8
caseCXR-2026-0852toolAnnalise CXRsealed2026-05-07 04:53:00Z · 47m agoprevc46d98…87c0f1
Click to verify →
fcf0…e6dfCXR-2026-0853
fcf0d27e31534501679a76f801e9291abd85149ffdc999941194a3c93855e6df
caseCXR-2026-0853toolEnlitic Curiesealed2026-05-07 05:04:00Z · 36m agoprevff8b19…606ff8
Click to verify →
febb…06bfBCT-2026-0854
febba551c829cb79d994e89ad476d1f9c7772d7d79cb1e315bab55d7132406bf
caseBCT-2026-0854toolAidoc PE Detectionsealed2026-05-07 05:10:00Z · 30m agoprevfcf0d2…55e6df
Click to verify →
da0c…0f60MMG-2026-0855
da0c4d1526765c82512b24518182cea1d286d3ca170d6115dedc0cc2b7c80f60
caseMMG-2026-0855toolLunit INSIGHTsealed2026-05-07 05:13:00Z · 27m agoprevfebba5…2406bf
Click to verify →
e5e1…a25aMRI-2026-0856
e5e1bce89de66f165094659458f7fb6754f25deaf6ad5bede7ca75a586aea25a
caseMRI-2026-0856toolBehold MRI Kneesealed2026-05-07 05:27:00Z · 13m agoprevda0c4d…c80f60
Click to verify →
6614…b55aBCT-2026-0857
6614270dbc4b3897b06f125b16af3269ecaf29183809961e53803c1bd46db55a
caseBCT-2026-0857toolHarrison CT Brainsealed2026-05-07 05:35:00Z · 5m agopreve5e1bc…aea25a
Click to verify →
2a97…ffe3CXR-2026-0858
2a971540cfd15abf745fd77c58b214a45ef5af5788f861d81ca7549930b5ffe3
caseCXR-2026-0858toolAnnalise CXRsealed2026-05-07 05:40:00Z · 0s agoprev661427…6db55a
Click to verify →
moirai

The evidentiary backbone for clinical AI oversight. Built around current Australian governance references.

Stay informed

Monthly digest of regulatory changes and clinical AI best practices.

Platform

  • Overview
  • Security
  • Trust Center
  • Pricing
  • Changelog
  • Demo

Proof

  • Research Ledger
  • Follow-up Preview
  • Public Verifier

Resources

  • Follow-up Preview
  • Security
  • Blog

Company

  • About
  • Contact
  • System Status

AU data sovereignty·Encryption at rest & in transit·Trust Center →

Trust signals

Hash VerifiedSHA-256 sealed
Enterprise SecurityAES-256, RLS, audit
External RefsRANZCR, TGA, Ahpra
Risk ControlsMonitoring + incidents
on the record.
Mapped toRANZCRChapter 9TGASaMDAhpraAI obligationsACSQHCNSQHSDISRAI plan
© 2026 Moirai Health Pty Ltd. All rights reserved.
Privacy PolicyTerms of ServiceSecurityTrust CenterDPA
All systems operational

Security architecture

Security evidence, on the record.

Moirai keeps clinical AI governance records isolated, encrypted, exportable, and verifiable. The security story is not a badge wall. It is a chain of custody a buyer can inspect.

Open evidence roomView DPA
Primary dataSydney AU
Practice scopeRLS enforced
Evidence custodyHash logged
PHI policyProhibited

Control plane

Active layer

Every record is filtered twice.

Follow-Up Evidence Pack
source record
evidence hash
reviewer mark
export ledger
Proof

RLS enforced

Ref

scope:practice

Application permission checks derive the practice from the authenticated profile, then database RLS enforces the same boundary at table level.

practice scoped
Current postureCertification limits stated

The useful version of trust is specific.

Security pages fail when they only say the safe words. This surface states what exists, what is prohibited, what is independently certified by vendors, and what Moirai has not yet completed.

policy boundary
PHI prohibited
records
metadata only
buyer path
DPA + room
IsolationPractice-scoped

Authenticated reads and writes are scoped through Supabase session cookies, server-side permission checks, and Row Level Security policies.

CustodyExport logged

Full exports and entity exports require audit permissions, are rate-limited, and append reviewer-visible activity events.

PHI boundaryProduct policy

Moirai is designed for governance metadata. PHI is prohibited and evidence uploads include conservative review flags.

CertificationRoadmap

Moirai does not yet hold SOC 2 or ISO 27001 certification. Current posture, limits, and planned assurance work are published in the Evidence Room.

Control map

Four layers buyers actually ask about.

The architecture reads from identity to public verification. Each layer exists because clinical governance records are sensitive even when they contain no patient data.

01

Identity and session

Supabase Auth issues httpOnly cookies. Protected routes refresh sessions through middleware before page or API access.

Cookie-based sessionsNo public service-role keysAPI 401 JSON boundary

02

Practice isolation

Application permissions derive the practice from the authenticated profile. Database RLS remains the second lock, not the only lock.

RBAC checked server-sidePractice-scoped RLSNo client-trusted role

03

Evidence custody

Uploads are validated for type, size, integrity hash, and PHI-risk signals before they can contribute to a Follow-Up Evidence Pack.

MIME and size validationSHA-256 file hashPHI review state

04

Public verification

The verifier exposes only PHI-excluding metadata for hashes, report IDs, and evidence events.

Zod validation firstRate-limited lookupExplicit safe fields

Data boundary

Governance data only.

Moirai is designed for governance metadata: AI tools, owners, approvals, evidence references, policies, reviews, and exports. Patient-identifiable health information is outside product policy.

PHI prohibited by product policyGovernance metadata only
Policy referenceSEC-REF-2026docs/SECURITY.md
01Practice userAuth session
02Server guardPermission check
03RLS policyPractice scope
04File exportActivity logged

Primary governance database

Sydney, Australia

Supabase managed Postgres in ap-southeast-2 is the primary data store for follow-up records and practice-scoped app data.

Operational sub-processors

Documented

Payments, analytics, error tracking, email, hosting, and AI-assisted product workflows use listed providers with stated purposes.

AI generation boundary

No patient data

AI assistance is limited to product workflow support. Patient data, medical images, and clinical reports are outside external tooling policy.

Sub-processors

The vendor layer is not hidden.

Due diligence should not require email archaeology. The review path links the DPA, security limits, and public verifier.

Test public verifier
ProviderPurposeLocationAssurance
SupabaseSupabase
Database, authentication, storageSydney, AU (ap-southeast-2)SOC 2 Type IIHIPAA
VercelVercel
Hosting, edge, serverless functionsSydney PoP, global edgeSOC 2 Type IIISO 27001
StripeStripe
Payments and billingUS / EUPCI DSS Level 1SOC 2
SeSentry
Error monitoring, performance telemetryUSSOC 2 Type IIGDPR
PoPostHog
Product analytics, feature flagsEUSOC 2 Type IIGDPR
ReResend
Transactional email deliveryUSSOC 2 Type II
LoLoops
Lifecycle email and user communicationsUSDPA listed
AnthropicAnthropic
Governance content generation (no patient data sent)USSOC 2 Type II

External references

Mapped means mapped.

These are evidence mapping references and certification roadmap items. They are not claims of regulator approval, clinical validation, or third-party certification.

Australian Privacy Act 1988mapped
OAIC APP Guidelinesmapped
RANZCR Chapter 9mapped
TGA medical-device software guidancemapped
SOC 2 Type IIroadmap
ISO 27001roadmap

Responsible disclosure.

Found a vulnerability? Email the security team directly. We take reports seriously and respond through the incident-response path.

security@moirai.health

Due diligence

Bring the evidence to procurement.

Open the Evidence Room for current posture, certification limits, sub-processors, documents, DPA, and public verification.

Open evidence roomView follow-up preview