Security
Security is designed in from the start, not bolted on.
Encryption
Data encrypted in transit and at rest.
Tamper-evident log
Audit events are append-only and tamper-evident.
Access control
Authentication via SMART on FHIR (OAuth 2.0); least-privilege access.
Canadian residency
Sensitive data hosted in Canada.
Incident response
Notification process aligned with regulatory obligations.