Security and Compliance

NodeAI has completed a SOC 2® Type II examination of its controls relevant to security, covering the period April 8, 2026 to July 7, 2026. The examination was performed by KEN & Co. CPA LLC, an independent CPA firm, under AICPA attestation standards (SSAE No. 18).

The report is available to customers, prospective customers, partners and their advisors on request under a mutual non-disclosure agreement. Contact info@nodeai.ca.

Where your data lives

NodeAI's production environment is hosted on Amazon Web Services in the Canada Central region. Research and model development infrastructure is hosted on Google Cloud Platform in the Montreal region. Clinical data does not leave Canada.

How the platform handles clinical data

The NodeAI platform processes anonymized ultrasound imaging data uploaded by clinical trial sites. It is intended for research use and does not currently support clinical diagnosis or treatment decisions, and does not process identifiable patient information. Formal retention and disposal procedures govern how research data is held and removed.

What this examination does not cover

The examination addressed the security trust services category only. It did not address availability, processing integrity, confidentiality or privacy. Physical and environmental controls are the responsibility of NodeAI's cloud hosting providers. A SOC 2® examination assesses information security controls and is not a regulatory clearance, a certification, or an assessment of clinical performance.

Questions about our security posture, or need the report? info@nodeai.ca