Skip to content
moirai
Product
Pricing
Buyers
Follow-up previewSynthetic follow-up evidence loopSecurityPrivacy and control posturePublic verifierHash-only evidence lookup
Research
Demo
Take the tour15-minute compatibility loopInteractive demoFollow-up status walkthroughBlogEvidence and operations notes
About
Sign inVerifyPreview
Menu
ProductPricing
Buyers
OverviewFollow-up previewSecurityPublic verifier
Research
Demo
OverviewTake the tourInteractive demoBlog
About
Sign inPreviewOpen Follow-up Preview
placeholder
  • Route3.00 kB
  • First-load255 kB
  • StatusBudget
Public ledger · Live
12 most recent records · click to verifyVerify a hash →
f60d…6495CXR-2026-0847
f60de9172ecabc80520a858d55dfbed0e2b81592e14e977747adba47ec416495
caseCXR-2026-0847toolAnnalise CXRsealed2026-05-07 04:03:00Z · 1h agoprevGENESIS
Click to verify →
0ee5…d64bBCT-2026-0848
0ee5c76a771351aeb9f5789dca3cae2ea0d17b927bccf4234c543667998ed64b
caseBCT-2026-0848toolAidoc PE Detectionsealed2026-05-07 04:12:00Z · 1h agoprevf60de9…416495
Click to verify →
8d13…8a63MMG-2026-0849
8d13c08f55491bceb02cfa16c2ab998182e7c8cc0430d353d50d33be1c238a63
caseMMG-2026-0849toolLunit INSIGHTsealed2026-05-07 04:24:00Z · 1h agoprev0ee5c7…8ed64b
Click to verify →
26dc…0b39BCT-2026-0850
26dca762f427713a5a07bb7a007d140efd6c2b707840f9518a37b664e39a0b39
caseBCT-2026-0850toolHarrison CT Brainsealed2026-05-07 04:31:00Z · 1h agoprev8d13c0…238a63
Click to verify →
c46d…c0f1MRI-2026-0851
c46d98269a4511d23796f04dda7bb4c23097f4d30fb38975ad3fd15bb587c0f1
caseMRI-2026-0851toolBehold MRI Spinesealed2026-05-07 04:35:00Z · 1h agoprev26dca7…9a0b39
Click to verify →
ff8b…6ff8CXR-2026-0852
ff8b19d90abe87a193139a04ea3e2f8dd63c952ad7a71ba6aeabf82fe4606ff8
caseCXR-2026-0852toolAnnalise CXRsealed2026-05-07 04:53:00Z · 47m agoprevc46d98…87c0f1
Click to verify →
fcf0…e6dfCXR-2026-0853
fcf0d27e31534501679a76f801e9291abd85149ffdc999941194a3c93855e6df
caseCXR-2026-0853toolEnlitic Curiesealed2026-05-07 05:04:00Z · 36m agoprevff8b19…606ff8
Click to verify →
febb…06bfBCT-2026-0854
febba551c829cb79d994e89ad476d1f9c7772d7d79cb1e315bab55d7132406bf
caseBCT-2026-0854toolAidoc PE Detectionsealed2026-05-07 05:10:00Z · 30m agoprevfcf0d2…55e6df
Click to verify →
da0c…0f60MMG-2026-0855
da0c4d1526765c82512b24518182cea1d286d3ca170d6115dedc0cc2b7c80f60
caseMMG-2026-0855toolLunit INSIGHTsealed2026-05-07 05:13:00Z · 27m agoprevfebba5…2406bf
Click to verify →
e5e1…a25aMRI-2026-0856
e5e1bce89de66f165094659458f7fb6754f25deaf6ad5bede7ca75a586aea25a
caseMRI-2026-0856toolBehold MRI Kneesealed2026-05-07 05:27:00Z · 13m agoprevda0c4d…c80f60
Click to verify →
6614…b55aBCT-2026-0857
6614270dbc4b3897b06f125b16af3269ecaf29183809961e53803c1bd46db55a
caseBCT-2026-0857toolHarrison CT Brainsealed2026-05-07 05:35:00Z · 5m agopreve5e1bc…aea25a
Click to verify →
2a97…ffe3CXR-2026-0858
2a971540cfd15abf745fd77c58b214a45ef5af5788f861d81ca7549930b5ffe3
caseCXR-2026-0858toolAnnalise CXRsealed2026-05-07 05:40:00Z · 0s agoprev661427…6db55a
Click to verify →
f60d…6495CXR-2026-0847
f60de9172ecabc80520a858d55dfbed0e2b81592e14e977747adba47ec416495
caseCXR-2026-0847toolAnnalise CXRsealed2026-05-07 04:03:00Z · 1h agoprevGENESIS
Click to verify →
0ee5…d64bBCT-2026-0848
0ee5c76a771351aeb9f5789dca3cae2ea0d17b927bccf4234c543667998ed64b
caseBCT-2026-0848toolAidoc PE Detectionsealed2026-05-07 04:12:00Z · 1h agoprevf60de9…416495
Click to verify →
8d13…8a63MMG-2026-0849
8d13c08f55491bceb02cfa16c2ab998182e7c8cc0430d353d50d33be1c238a63
caseMMG-2026-0849toolLunit INSIGHTsealed2026-05-07 04:24:00Z · 1h agoprev0ee5c7…8ed64b
Click to verify →
26dc…0b39BCT-2026-0850
26dca762f427713a5a07bb7a007d140efd6c2b707840f9518a37b664e39a0b39
caseBCT-2026-0850toolHarrison CT Brainsealed2026-05-07 04:31:00Z · 1h agoprev8d13c0…238a63
Click to verify →
c46d…c0f1MRI-2026-0851
c46d98269a4511d23796f04dda7bb4c23097f4d30fb38975ad3fd15bb587c0f1
caseMRI-2026-0851toolBehold MRI Spinesealed2026-05-07 04:35:00Z · 1h agoprev26dca7…9a0b39
Click to verify →
ff8b…6ff8CXR-2026-0852
ff8b19d90abe87a193139a04ea3e2f8dd63c952ad7a71ba6aeabf82fe4606ff8
caseCXR-2026-0852toolAnnalise CXRsealed2026-05-07 04:53:00Z · 47m agoprevc46d98…87c0f1
Click to verify →
fcf0…e6dfCXR-2026-0853
fcf0d27e31534501679a76f801e9291abd85149ffdc999941194a3c93855e6df
caseCXR-2026-0853toolEnlitic Curiesealed2026-05-07 05:04:00Z · 36m agoprevff8b19…606ff8
Click to verify →
febb…06bfBCT-2026-0854
febba551c829cb79d994e89ad476d1f9c7772d7d79cb1e315bab55d7132406bf
caseBCT-2026-0854toolAidoc PE Detectionsealed2026-05-07 05:10:00Z · 30m agoprevfcf0d2…55e6df
Click to verify →
da0c…0f60MMG-2026-0855
da0c4d1526765c82512b24518182cea1d286d3ca170d6115dedc0cc2b7c80f60
caseMMG-2026-0855toolLunit INSIGHTsealed2026-05-07 05:13:00Z · 27m agoprevfebba5…2406bf
Click to verify →
e5e1…a25aMRI-2026-0856
e5e1bce89de66f165094659458f7fb6754f25deaf6ad5bede7ca75a586aea25a
caseMRI-2026-0856toolBehold MRI Kneesealed2026-05-07 05:27:00Z · 13m agoprevda0c4d…c80f60
Click to verify →
6614…b55aBCT-2026-0857
6614270dbc4b3897b06f125b16af3269ecaf29183809961e53803c1bd46db55a
caseBCT-2026-0857toolHarrison CT Brainsealed2026-05-07 05:35:00Z · 5m agopreve5e1bc…aea25a
Click to verify →
2a97…ffe3CXR-2026-0858
2a971540cfd15abf745fd77c58b214a45ef5af5788f861d81ca7549930b5ffe3
caseCXR-2026-0858toolAnnalise CXRsealed2026-05-07 05:40:00Z · 0s agoprev661427…6db55a
Click to verify →
moirai

The evidentiary backbone for clinical AI oversight. Built around current Australian governance references.

Stay informed

Monthly digest of regulatory changes and clinical AI best practices.

Platform

  • Overview
  • Security
  • Trust Center
  • Pricing
  • Changelog
  • Demo

Proof

  • Research Ledger
  • Follow-up Preview
  • Public Verifier

Resources

  • Follow-up Preview
  • Security
  • Blog

Company

  • About
  • Contact
  • System Status

AU data sovereignty·Encryption at rest & in transit·Trust Center →

Trust signals

Hash VerifiedSHA-256 sealed
Enterprise SecurityAES-256, RLS, audit
External RefsRANZCR, TGA, Ahpra
Risk ControlsMonitoring + incidents
on the record.
Mapped toRANZCRChapter 9TGASaMDAhpraAI obligationsACSQHCNSQHSDISRAI plan
© 2026 Moirai Health Pty Ltd. All rights reserved.
Privacy PolicyTerms of ServiceSecurityTrust CenterDPA
All systems operational

Trust Center

Evidence room. Security control plane.

Vendor review without the scavenger hunt. This page shows the current security posture, data boundary, buyer documents, public verifier path, and the limits Moirai will not overclaim.

Posture reviewed 12 May 2026·Next review 12 June 2026

Security Control Plane

Current trust state

No PHI boundary
01Posture

Limits declared

02DPA

Terms inspectable

03Sample file

Evidence visible

04Verifier

Hash checkable

Identity

Practice scope

Practice-scoped data isolation

Row Level Security on all tables

Custody

Encrypted

AES-256 encryption at rest

TLS 1.3 in transit

Residency

Primary AU

Primary data in Sydney (ap-southeast-2)

Listed sub-processors documented

Incident path

NDB assessed

NDB assessment process documented

Founder-led response with vendor escalation

Public verifier

Hash and report metadata can be checked without exposing patient data.

Posture

Documents

Verify

Limits ledger

SOC 2

Not certified yet

Moirai does not yet hold SOC 2 or ISO 27001 certification. Vendor infrastructure controls are documented, but Moirai's own control audit is still on the roadmap.

Penetration testing

Planned

Independent penetration testing is not yet complete. A summary will be available to qualified buyers after the first external test and remediation pass.

Patient data

Prohibited

Product policy prohibits PHI uploads. The platform is designed for governance metadata, evidence references, policies, approvals, and audit records.

Inspect and verify

Inspect the synthetic follow-up evidence, then test the public verification path before a founder call.

Open follow-up previewOpen public verifier
01

Data Processing Agreement

Data handling, sub-processors, breach notification, international transfers, and audit provisions.

Open DPA
02

Follow-up preview

Synthetic follow-up evidence record, verification snapshot, and source-to-status proof trail.

Inspect preview
03

Public verifier

No-auth verification endpoint for report fingerprints and PHI-safe chain metadata.

Open verifier

Posture ledger

What is not certified yet

The useful version of trust is specific. These are the current limits a buyer should understand before procurement.

SOC 2

Not certified yet

Moirai does not yet hold SOC 2 or ISO 27001 certification. Vendor infrastructure controls are documented, but Moirai's own control audit is still on the roadmap.

Penetration testing

Planned

Independent penetration testing is not yet complete. A summary will be available to qualified buyers after the first external test and remediation pass.

Medical-device scope

Out of scope

Moirai is governance infrastructure. It does not diagnose, triage, interpret images, process medical images, recommend treatment, or replace clinician judgment.

Patient data

Prohibited

Product policy prohibits PHI uploads. The platform is designed for governance metadata, evidence references, policies, approvals, and audit records.

Assurance sequence

Security roadmap

The order matters: publish the current posture first, then add independent evidence as the commercial risk justifies it.

Now

Evidence-room baseline

Publish current controls, data boundaries, sub-processors, DPA, privacy terms, incident-response process, and explicit certification limits.

Next

Independent penetration test

Commission third-party penetration testing, remediate findings, and make an executive summary available under NDA.

After paid pilots

SOC 2 readiness

Formalise access reviews, vendor review cadence, change management evidence, incident drills, and control-owner accountability.

Scale stage

ISO 27001 scoping

Scope the information security management system once customer volume and enterprise procurement demand justify the audit cost.

AES-256

Encryption

99.9%

Uptime Target

Australia

Data Residency

<30d

NDB Assessment

Evidence RoomCurrent PostureRoadmapRegulatory MappingSecurityData HandlingSub-processorsDocumentsUptime & SLADisclosureFAQ

PHI prohibited by product policy

Product policy prohibits PHI uploads. The platform is designed for governance metadata, evidence references, policies, approvals, and audit records.

Regulatory mapping

Built to organise evidence against Australian healthcare obligations, with a clear path to independent security certifications.

Australian Privacy Act 1988

Mapped

OAIC APP Guidelines

Mapped

RANZCR Ch.9 mapped

Mapped

Ahpra AI guidance

Mapped

TGA medical software guidance

Mapped

ACSQHC AI guidance

Mapped

NIST Cybersecurity Framework

Planned

ISO 27001

Planned

External references

RANZCRChapter 9TGASaMDAhpraAI obligationsNHMRCAI ethicsNATAAccreditation

Mapped to current guidance · No endorsement claimed

Security controls

Every layer of the Moirai stack is designed with security as a constraint, not an afterthought.

Encryption

  • AES-256 encryption at rest
  • TLS 1.3 in transit
  • Encrypted automated backups
  • Key rotation and management

Data Residency

  • Primary data in Sydney (ap-southeast-2)
  • Supabase managed Postgres in AU
  • Australian Privacy Act jurisdiction
  • Listed sub-processors documented

Access Control

  • Row Level Security on all tables
  • Practice-scoped data isolation
  • Cookie-based auth sessions
  • Role-based access control (RBAC)

Infrastructure

  • Vercel edge network with global CDN
  • Supabase managed Postgres with HA
  • Automated daily backups with PITR
  • DDoS protection and WAF

Incident Response

  • 24-hour incident response SLA
  • NDB assessment process documented
  • Founder-led response with vendor escalation
  • Post-incident review and disclosure

Business Continuity

  • Multi-region edge deployment
  • Managed infrastructure failover
  • Point-in-time recovery (PITR)
  • Regular disaster recovery testing

Data handling

Your governance data stays under your control. We store only what is needed and give you full export and deletion capabilities.

Data residency

Primary governance database and storage run in Sydney, Australia (ap-southeast-2). Listed sub-processors may process operational metadata offshore.

Data portability

Full export of your data in JSON and CSV formats at any time. Your data is yours.

Data retention

Configurable retention policies. Data preserved for 30 days after account cancellation.

No third-party sharing

Your governance data is never shared with third parties beyond essential service providers listed below.

Sub-processors

A transparent list of third-party services that process data on behalf of your practice.

ProviderPurposeData locationAssurance
SupabaseSupabase
Database, authentication, storageSydney, AU (ap-southeast-2)SOC 2 Type IIHIPAA
VercelVercel
Hosting, edge, serverless functionsSydney PoP, global edgeSOC 2 Type IIISO 27001
StripeStripe
Payments and billingUS / EUPCI DSS Level 1SOC 2
Sentry
Error monitoring, performance telemetryUSSOC 2 Type IIGDPR
PostHog
Product analytics, feature flagsEUSOC 2 Type IIGDPR
Resend
Transactional email deliveryUSSOC 2 Type II
Loops
Lifecycle email and user communicationsUSDPA listed
AnthropicAnthropic
Governance content generation (no patient data sent)USSOC 2 Type II

Documents & reports

Security documentation for your due diligence review. Available documents can be accessed directly; others are available on request.

Available

Data Processing Agreement

Covers data handling, sub-processors, breach notification, and data subject rights.

View document
Available

Privacy Policy

How we collect, use, and protect your information under Australian privacy law.

View document
Available

Terms of Service

Service terms, acceptable use, liability, and dispute resolution.

View document
Q3 2026

Security Whitepaper

Detailed breakdown of our security architecture, controls, and practices.

Request access

Penetration Test Summary

Third-party penetration testing results and remediation summary.

Request access
Request access

Security Questionnaire

Pre-filled SIG Lite, CAIQ, and custom security questionnaire responses.

Request access

Uptime & SLA

Built on infrastructure trusted by millions of production applications.

99.9%

Uptime SLA

  • Vercel edge network with global CDN
  • Supabase managed Postgres with HA
  • Automated failover and PITR backups
  • 24/7 infrastructure monitoring

All systems operational

Real-time status monitoring

View current system status, historical uptime, and subscribe to incident notifications on our status page.

Visit status page

Infrastructure powered by

VercelVercel
SupabaseSupabase
StripeStripe
AnthropicAnthropic

Responsible disclosure

Found a vulnerability? We take security reports seriously and respond to every submission. Please disclose responsibly by emailing our security team directly.

security@moirai.health

Frequently asked questions

Common questions from security and compliance teams during vendor review.

Does Moirai store patient data?

Moirai is designed for governance metadata: which AI tools are used, who approved them, what policies exist, and how governance decisions were documented. Product policy prohibits uploading Protected Health Information (PHI).

Where is my data stored?

The primary governance database and storage are in Sydney, Australia (ap-southeast-2) on Supabase managed Postgres. Listed sub-processors may process operational metadata offshore for payments, analytics, email, and error tracking.

Can I export my data?

Yes. You can export your complete governance dataset in JSON and CSV formats at any time from the Settings page. Your data is yours.

How do you handle security incidents?

We maintain a documented incident response process. Under the Notifiable Data Breaches scheme, we assess suspected eligible data breaches within 30 days and notify OAIC and affected individuals as soon as practicable when notification is required.

Do you have a Data Processing Agreement?

Yes. Our DPA covers data handling, sub-processors, breach notification, international transfers, data subject rights, and audit provisions. It's available at moirai.health/legal/dpa.

What certifications do you have?

Moirai itself does not yet hold SOC 2 or ISO 27001 certification. It is built on certified infrastructure and designed to support obligations under the Australian Privacy Act 1988 and OAIC Australian Privacy Principles. Clinical AI governance evidence is mapped against RANZCR Chapter 9, Ahpra AI guidance, TGA medical-device software guidance, ACSQHC AI guidance, and DISR AI adoption materials.

Get the full security pack

Security questionnaire responses, penetration test summary, architecture diagrams. Or schedule a call with our team.

Request security packView the follow-up preview