Identity and authorization
Keyra is the trust layer contract for verified identity. Authentication is not authority. Every protected request evaluates live authorization on the server.
Encryption and sessions
TLS in transit. Encryption at rest in the deployed environment. HttpOnly sessions with SameSite controls. Envelope encryption is prepared for highly sensitive fields.
Consent and audit
Purpose-bound, time-bounded authorizations with readable receipts. Append-only, hash-chained audit events. Historical audit records are never mutated.
AI and clinical governance
Material model outputs carry provenance. Candidate biomedical models remain unapproved for PHI until validated. The platform never prescribes; qualified clinical authority governs medical action.
Data sovereignty and operations
Jurisdiction-aware residency is architected. Incident and vulnerability channels exist. Subprocessors are listed as they are contracted—not invented for appearance.