Security and Compliance
NodeAI has completed a SOC 2® Type II examination of its controls relevant to security, covering the period April 8, 2026 to July 7, 2026. The examination was performed by KEN & Co. CPA LLC, an independent CPA firm, under AICPA attestation standards (SSAE No. 18).
The report is available to customers, prospective customers, partners and their advisors on request under a mutual non-disclosure agreement. Contact info@nodeai.ca.
Where your data lives
NodeAI's production environment is hosted on Amazon Web Services in the Canada Central region. Research and model development infrastructure is hosted on Google Cloud Platform in the Montreal region. Clinical data does not leave Canada.
How the platform handles clinical data
The NodeAI platform processes anonymized ultrasound imaging data uploaded by clinical trial sites. It is intended for research use and does not currently support clinical diagnosis or treatment decisions, and does not process identifiable patient information. Formal retention and disposal procedures govern how research data is held and removed.
-
Datastores holding sensitive customer data are encrypted at rest
TLS is enforced for data transmitted over public networks, with certificate validity and strong cipher suites verified
Backups are encrypted, with access limited to designated personnel
Portable and removable media are encrypted where used
-
Role-based access on a least-privilege model, with admin and user roles separated
Multi-factor authentication required for remote access to production systems
Unique credentials or authorized SSH keys required for all system and service accounts
Privileged access to databases, operating systems, firewalls and the production network restricted to documented business need
User access reviewed quarterly, with required changes tracked to completion
Documented provisioning, modification and revocation procedures, including termination checklists
-
Segmented virtual private cloud with separate public and private subnets
Firewalls configured to block unauthorized access, with rulesets reviewed at least annually
Intrusion detection providing continuous network monitoring and alerting
Administrative access to research infrastructure brokered through an identity-aware proxy rather than direct remote access
Network and system hardening standards documented against industry practice and reviewed annuallyDescription text goes here
-
Centralized log management with 365-day retention and access limited to authorized users
Infrastructure monitoring with alerting on predefined performance and capacity thresholds
Endpoint anti-malware and mobile device management across company devices
-
Host-based vulnerability scans on external-facing systems at least quarterly
Automated scanning of source code and open-source dependencies
Penetration testing performed at least annually by an external partner, with remediation tracked against internal service levels
Infrastructure patched as routine maintenance and in response to identified vulnerabilities
-
Documented secure development lifecycle governing changes, including emergency changes
Development and testing environments logically separated from production
Changes documented, tested and reviewed by someone other than the author before release
Branch protection enforced, with deployment rights restricted to authorized personnel
Infrastructure provisioned as code, with container images promoted by pinned digest for traceability
-
Documented incident response plan, tested at least annually
Documented business continuity and disaster recovery plan, tested at least annually
Customer data backed up, with completion and exceptions monitored
Cybersecurity insurance maintained
-
Virtual Chief Information Security Officer advisory services provided by Workstreet
Continuous control monitoring through Vanta
Annual risk assessment covering environmental, regulatory and technological change, including fraud risk
Vendor management program with an inventory of critical vendors reviewed at least annually
Security awareness training at hire and annually thereafter
Background checks and confidentiality agreements for personnel
Board briefed at least annually on cybersecurity and privacy risk
Information security policies reviewed at least annually
Anonymous whistleblower channel
What this examination does not cover
The examination addressed the security trust services category only. It did not address availability, processing integrity, confidentiality or privacy. Physical and environmental controls are the responsibility of NodeAI's cloud hosting providers. A SOC 2® examination assesses information security controls and is not a regulatory clearance, a certification, or an assessment of clinical performance.
Questions about our security posture, or need the report? info@nodeai.ca