Skip to main content
Security and privacy

How we protect clinical information.

This page documents the controls applied to access, encryption, infrastructure, AI usage and data life cycle within Brauni.

Check the controls

Last documentary review: March 2026

Clinical fields

Application Encryption with Fernet (AES-128)

Communications

TLS 1.3 during the transit of information

Access

Authentication in two steps and passkeys

Use of AI

Contractual restrictions on non-training

Privacy of Brauni AI

Clinical data are not used to train models.

The context is processed to respond to the request you make within Brauni, under business agreements with AI providers.

How it works Brauni AI

Authorized context

Brauni AI processes the sessions, documents or patients you select for a particular task.

Limited use

The information is used to generate the requested response within the product.

No training

Business agreements with suppliers prevent the use of such content to train models.

Professional review

The results are drafts or analyses that the professional checks before incorporating them into his work.

Controls applied to each layer.

No control solves security alone. Brauni combines measures on the account, application, providers and life cycle of information.

Number

Information is protected during transmission, within the application and in the infrastructure where it is stored.

Clinical fields

Session notes, medical records, and other sensitive fields are encrypted at the application level with Fernet (AES-128) before persisting.

Data in transit

Communication between your device and Brauni uses TLS 1.3.

Infrastructure

Databases and storage also operate on the rest encryption layers provided by AWS.

Key management

Keys are managed separately from data using AWS Key Management Service.

Access to the account

The password does not have to be the only entry barrier to clinical practice.

Second factor

You can activate temporary codes using an authenticating application.

Passkeys

Brauni supports WebAuthn-based access keys, including biometrics and compatible physical keys.

Active sessions

From the security settings you can check the connected devices and close sessions remotely.

Register of revenue

Logins and other relevant events are recorded with date, time and device.

Infrastructure and recovery

Brauni works on AWS with backups and incident recovery mechanisms.

Backups

The information has automatic backups and recovery to an earlier point in time.

Redundancy

The architecture distributes components to reduce the impact of an individual failure.

Deployments

Changes to the platform follow automated integration and deployment processes.

Data control

Clinical practice information is still under the control of the professional who loads it.

Export

You can request an export of patients, notes, stories, reports and documents in standard formats.

Portability

Structured data are delivered in formats such as CSV and JSON; documents retain their original format when applicable.

Closure of account

The account remains in read-only mode during the reporting period for export and then begins the elimination process set out in the terms.

Secondary use

Clinical data are not reused for advertising, benchmarking or model training.

Traceability

Important account events can be reviewed to investigate accesses and changes.

Registered events

Revenues, security changes and relevant actions are recorded on the account.

Exceptional support

A support intervention on sensitive information requires authorisation, limited scope and registration of action.

Review

Records help to reconstruct what happened to an incident or a security consultation.

Safety questions

Answers about access, suppliers, devices and account closure.

Security contact

Do you need documentation or did you find a vulnerability?

Write to us to request technical information, consult a specific control or report a safety problem.

Writing