Compliance · Security · Digital health

Compliance
isn’t a checkbox.

Four regulatory and security frameworks. Independent annual audits. Public Trust Center with continuous evidence. This is what sets us apart from a generic telemedicine app.

Open Trust Center Request formal evidence
01 / Health standard Certified

NOM-024-SSA3-2012

Mexican standard that regulates Electronic Health Record Information Systems (SIRES). Our electronic clinical record has operated in conformance with this standard from day one, audited before the Ministry of Health.

  • Standardized clinical data structure
  • Traceability and immutability of the record
  • Advanced electronic signatures for healthcare professionals
  • Interoperability with other certified SIRES systems
02 / Health standard Certified

NOM-004-SSA3-2012

The standard for the traditional clinical record, the foundation of medical documentation in Mexico. Our platform respects its structure, mandatory sections and document retention requirements.

  • Structured medical notes (subjective, objective, assessment, plan)
  • Retention for at least five years in conformance with the standard
  • Unequivocal identification of the patient and the treating professional
03 / Info security Certified

ISO/IEC 27001:2022

Information Security Management System audited by an independent body, reviewed annually. It covers our entire operation: infrastructure, devices, vendors, data lifecycle.

  • 114 Annex A controls implemented and monitored
  • Formal risk analysis and documented treatment plan
  • Mandatory security training for the entire team
  • Incident management with response SLAs
04 / Audit Type II

SOC 2 Type II

Audit under the AICPA framework with Insight Assurance. Continuous evaluation of Security, Availability, Processing integrity, Confidentiality and Privacy controls.

  • 12-month observation period in progress
  • Trust Service Criteria 2017 with 2022 revisions
  • Type II report available under NDA once the period closes
Additional compliance

Beyond
the certifications.

LFPDPPP

Mexico’s Federal Law on Protection of Personal Data Held by Private Parties. Public Privacy Notice, designated Data Officer, ARCO procedure in fewer than 20 business days.

Data in national territory

Servers in Mexico. No international transfers requiring additional consent. Immutable logs available for regulatory audits.

NOM-035 (enterprise clients)

When we operate health benefits for companies, we integrate with their NOM-035 obligations (psychosocial risk factors), generating auditable reports.

Verifiable, not self-declared

Does your legal or compliance team
need formal evidence?

We share issued certificates, audit reports under NDA, control matrix, incident handling policy and recent pentest results. All through our self-service Trust Center.