URIEL™ — Data Protection & Governance
Your governance, not ours.
URIEL is deployed inside an institution’s existing data protection posture, under its governance, with defined retention. This page sets out what that means in practice, and what we will not do.
The commitments
Five things an information security team will ask.
01
No model training on your data
Client inputs, session state and decision records are not used to train public or foundational models. We do not sell data, and we do not train shared models on identifiable institutional data.
02
HIPAA alignment and PHI demarcation
URIEL operates as a decision layer alongside your systems rather than inside your patient record. In the United States, handling is HIPAA-aligned, and deployments are scoped so the platform does not require Protected Health Information in order to function. Business Associate Agreements are addressed as part of scoping, not assumed.
03
UK GDPR and the Data Protection Act 2018
For United Kingdom deployments, processing follows UK GDPR and the Data Protection Act 2018 — data minimisation, a defined lawful basis, defined retention, and the institution as controller.
04
Caldicott Principles and NHS DSPT
In health and social care settings, deployments are scoped against the Caldicott Principles and the NHS Data Security and Protection Toolkit: justify the purpose, use the minimum necessary, and keep accountability with a named person.
05
What the concierge on this site does
The concierge is client-side. What you type into it is read in your own browser to work out where to take you. Your salutation is held in that browser session only, and is cleared when you close the tab. It is not sent to a server, not stored, and not recorded in analytics.
Certification status
SOC 2 certification is in progress. We say that plainly rather than imply more, and reviewers are welcome to ask where in the process we are. In the interim, deployments run inside the institution’s own security perimeter and are scoped against its existing controls.
URIEL is non-diagnostic. It is not a medical device, not a therapist, and not a replacement for clinical judgment. The FAQ answers the governance, liability and regulatory questions in more detail, and a conversation can be scoped against your own controls.
Ask us the hard version of these questions.
Deployments are scoped with the institution, under its governance, and inside its data protection posture.