Pensieve Labs

Search the register

Search all 478 artefacts by title, document ID or content.

Unlock NDA tier

Pensieve Labs | Edsol Edtech Pvt. Ltd. | Trust Center

Pensieve is the operating system for hospitals.

Everything a hospital’s legal, security, finance and IT teams need to evaluate us is on this page, most of it without asking.

The evidence pack is one zip of every public document, rebuilt nightly. Accepting the mutual NDA is one click and recorded at once. Those 128 documents open once an administrator approves your access request, with a target of four business hours.

The register

Compiled 01 August 2026

Artefacts on the register
491

Each classified on five independent axes: kind, tier, direction, lifecycle stage and state.

Words of published text
12,07,999

Written in full, not summarised. Every document on this site is the document, not a description of one.

On the critical path to cash
228

46% of the register directly gates the clock from first contact to funds credited.

Jurisdictions
7

GL, IN, AU, EU, DK, NO, AE: a global master with national variants where the substance differs.

Public108No gate | zero
Email5Give a work email | zero: instant
NDA128Accept the mutual NDA | target 4 business hours
Client141Sign in to your workspace | target 4 business hours
Internal109Administrator access only | n/a

108 open with no gate at all. 5 behind the one self-service gate, a work email, cleared in a single step. 269 behind an access request an administrator approves, target four business hours: the NDA tier and each hospital’s own workspace. 109 are internal to Pensieve, listed and counted here, because concealing the count would be the same mistake in a smaller costume.

Read this before you read anything else

Pensieve holds no security certifications. Here is the whole position.

A buyer finds the gaps eventually. Finding them here, in minute one, takes the discovery out of the security review, and every discovery taken out of the security review is days off the clock. The third column below is the one that matters, so it is the same width as the other two.

What we have today

Published, dated and readable right now, without a call and without a credential.

  • The complete standard paper

    MSA, DPA, SLA, mutual NDA and the order-form structure, published in full before anybody asks. Counsel can raise redlines on day one instead of day twenty.

    MSA-IN-001DPA-GL-001SLA-GL-001NDA-GL-002
  • ISO/IEC 27001:2022 Statement of Applicability

    All 93 Annex A controls assessed and published, with each one marked implemented, partial, not implemented or inherited. Uncertified, and labelled so on every page.

    STM-GL-010
  • Self-assessed CAIQ v4 and CAIQ-Lite

    The CSA questionnaire most hospital security reviews send us, answered in advance. Self-assessed, not audited. The document says that in its title.

    QRE-GL-005QRE-GL-006
  • Security whitepaper and architecture overview

    How Pensieve is built, run and defended, written per deployment model so a control that holds for DM-1 is never quietly claimed for DM-4.

    WPR-GL-001WPR-GL-002
  • Software Bill of Materials

    Third-party and open-source dependency disclosure, with the licence position and the patching commitment attached.

    DIS-GL-019
  • Live sub-processor register

    Who processes what, where, under which model, with a change feed you can subscribe to rather than a PDF that ages.

    DIS-GL-009
  • Framework mappings

    SOC 2 Trust Services Criteria, CIS Controls v8, NIST CSF 2.0, GDPR Article 28, DPDP and the CERT-In Directions, each mapped to the evidence that answers it.

    CHK-GL-029CHK-GL-030CHK-GL-031CHK-GL-033
  • A published vulnerability disclosure policy

    With safe harbour, a one-business-day human acknowledgement and named remediation targets by severity.

    POL-GL-059
  • 108 documents at the public tier

    Not a summary page. The instruments themselves, versioned, hashed and dated, with a review date on every one.

    Open the public tier

What we are doing next

Each with a published owner, a target date and a milestone list we can be held to in public.

  • ISO/IEC 27001:2022 certification

    No audit has commenced. The Statement of Applicability is already published; the readiness statement carries the target date, the programme owner, the budget status and the milestone list. If the date is missed it is re-dated with a reason rather than quietly deleted.

    STM-GL-011
  • SOC 2: after ISO, deliberately

    No examination has commenced and no CPA firm is engaged. The readiness statement puts the reasoning for that order on the record so you can disagree with it in week one rather than week six.

    STM-GL-012
  • Independent penetration test

    Not yet performed. What is published is the attestation the testing firm will sign on its own letterhead (scope, methodology, tester credentials, severity distribution, re-test and residual risk) so the deliverable is fixed before the engagement is.

    REP-GL-001
  • CERT-In empanelled VAPT

    Not yet performed. The safe-to-host certificate format and the release control around it are published now.

    REP-GL-004
  • Published security grades

    Targets are stated in public (SSL Labs A+, Security Headers A, HSTS preload) and the snapshot tells you how to re-run every one of them yourself, against this domain, without our cooperation, in five minutes.

    REP-GL-017
  • Quarterly scan summary

    SAST, SCA, container and IaC results published on a cadence, because the evidence that matters is a pipeline that finds things and closes them.

    REP-GL-016

What we do not have

Stated first, by us, in the same type size as everything else on this page.

  • No ISO/IEC 27001 certificate

    None held. No certification body engaged, no Stage 1 audit, no Stage 2 audit. A hospital that requires a current certificate at signature should treat that as a blocker today.

    STM-GL-011
  • No SOC 2 report, Type I or Type II

    None held and none commenced. SOC 2 produces a report containing a practitioner's opinion. It does not produce a certificate, and no organisation is “SOC 2 certified”. We will not use the phrase.

    STM-GL-012
  • No HITRUST CSF certification

    None held, and not on the near-term path. It is not the credential the markets Pensieve sells into ask for.

  • No CE marking under EU MDR

    Pensieve is not placed on the market as a medical device and makes no diagnostic or treatment claim. The boundary is written down rather than left to be inferred.

    DIS-GL-028
  • No ARTG listing with the TGA

    Same boundary, same document, for Australia. A hospital deploying Pensieve as part of a regulated clinical device workflow is the sponsor of that workflow, not Pensieve.

    DIS-GL-028
  • No ABDM M1/M2/M3 and no NHCX participant status

    Deliberately out of scope, and this is an architectural decision rather than a gap. The hospital is the registered facility: it holds its own HFR facility ID, its clinicians hold their own HPR IDs, and it holds its own NHCX credentials. Pensieve stores them encrypted per tenant and calls those systems as the hospital, on the hospital's own authority. Pensieve is therefore not the regulated participant and never represents that it is.

    DIS-GL-024DIS-GL-025ABDM, NHCX and the BYOK boundary

Start here

The 8 documents that decide most evaluations

These are the ones a hospital’s security, legal and IT reviewers ask for first. All of them are published at the public tier, in full, with a version, a content hash and a review date on every page.

The full library

Read this first. A security claim that is true for DM-1 can be false for DM-4. Every section of this document that is deployment-model-sensitive carries a per-model table or a variant note. Where you see a claim without…

WPR-GL-001WhitepaperGL1234PublicCritical path31 July 2026

This document is for the person who has to decide whether Pensieve can be operated safely inside a hospital: the IT head, the group CIO, the incumbent maintenance partner, or an external reviewer.

WPR-GL-002DisclosureGL1234PublicCritical path01 August 2026

This document is the single source of truth for the definitions of DM-1 to DM-4. Every other Pensieve Labs artefact references these definitions rather than restating them.

WPR-GL-004WhitepaperGL1234PublicCritical path31 July 2026

This is the standard form on which Edsol Edtech Pvt. Ltd. contracts. It is published openly, in full, before any commercial conversation, so that a hospital's counsel can read it, price the risk in it, and raise…

MSA-IN-001ContractIN1234PublicCritical path31 July 2026

This is the standard service level on which Edsol Edtech Pvt. Ltd. contracts. It is published in full, before any commercial conversation, so that a hospital can read the commitment, the measurement method and the…

SLA-GL-001ContractGL1234PublicCritical path31 July 2026

Section 3 (Trust Center and corporate) applies in all four models, because every hospital that buys Pensieve also uses the Trust Center to receive documents, and no deployment model changes that.

DIS-GL-009DisclosureGL1234PublicCritical path31 July 2026

Your data is yours. All of it. At any time. In a form you can use. At no charge. However this ends, including if it ends because you did not pay us.

WPR-GL-400WhitepaperGL1234PublicCritical path31 July 2026

By reviewer

Four hubs, each written for one person

The same register, entered from four directions. Every hub leads with the documents that reader actually opens rather than whatever sorts first alphabetically, and says how many more sit behind it.

For the hospital's IT head, CISO or security reviewer

Security

How Pensieve is built, run and defended, and where each claim stops being true, because a control that holds for a dedicated deployment can be the hospital's responsibility on-premise.

82 documents | 77 more not shownOpen the security hub

For the data protection officer, company secretary or compliance lead

Privacy

The DPDP position, the processing agreement, retention, deletion, data-principal rights and the grievance route: for Pensieve as processor, and for this Trust Center where Pensieve is a fiduciary in its own right.

76 documents | 71 more not shownOpen the privacy hub

For the hospital's advocate or external counsel

Legal

The standard paper, published in full before anybody asks for it. Reading the MSA, DPA and SLA on day one is what lets counsel raise redlines on day six instead of day twenty.

59 documents | 54 more not shownOpen the legal hub

For the IT lead or an external technology adviser

Architecture

What Pensieve is, how it is deployed, what it talks to, and where the boundary of Pensieve's responsibility sits in each of the four deployment models.

41 documents | 36 more not shownOpen the architecture hub

Updates

What changed, and when

Security bulletins, sub-processor changes, document revisions and the monthly overdue review list. Sub-processor changes are announced before they take effect, not after.

The bulletin feed could not be read.

Bulletins are served from the database and this page does not cache them, so a database outage shows up here first. Everything else on this page is compiled from the register itself and is unaffected. Try the updates page or subscribe by RSS, which is generated separately.

Report a vulnerability

Found a defect? Tell us, and we will answer you.

A defect found by a researcher and reported to us is worth more than the same defect found by an attacker. The disclosure policy carries safe harbour, a human acknowledgement within one business day, initial triage within three, and named remediation targets by severity: critical findings mitigated within 24 hours.

If you believe patient data is exposed, say so in the first line of the message and write to the same address. That report is treated as an incident, not as a research submission, and it is escalated the moment it is read.