Accept the mutual NDA to request access to this tier. Your acceptance is recorded at once and protects both sides; an administrator then grants access, with a target of four business hours.Accept the mutual NDAWait: four business hours (target)
Pensieve Labs | Trust Center
Governed Intelligence for Every Decision
Pensieve powers the real-time, governed decisions that run the public and private hospitals a nation depends on, from the emergency room to the audit trail.
The mutual NDA is accepted online and recorded on acceptance. The 396 documents behind it open on approval of an access request. The published target is four business hours.
The register
Compiled 30 August 2026
- Artefacts on the register
- 713
- Published without a gate
- 22
- Required before signature
- 377
- Jurisdictions
- 7
Each is the instrument itself, classified, versioned, hashed and dated.
Readable in full, now, with no account and no request.
53% of the register is read, negotiated or relied on by a hospital before a contract is executed.
A global master with national variants wherever the substance differs: GL, IN, AU, EU, DK, NO, AE.
7 require nothing beyond a work email. 557 require an approved access request: the NDA tier and each hospital’s own workspace. 127 are internal to Pensieve. Their titles are withheld. Their existence and their count are not.
Assurance position
Pensieve holds no security certifications.
Every certification Pensieve does not hold is named below, with the reason and the current status of each. Where no audit has commenced, the entry says so. Where a date has been set, the owner and the milestone list are published with it.
Held today
Published in full, versioned and dated. No account required.
The complete standard paper
MSA, DPA, SLA, mutual NDA and the order-form structure, published in full. Counsel can begin redlining without requesting anything.
MSA-IN-001DPA-GL-001SLA-GL-001NDA-GL-002ISO/IEC 27001:2022 Statement of Applicability
All 93 Annex A controls assessed and published, each marked implemented, partial, not implemented or inherited. Uncertified, and marked as such on every page.
STM-GL-010Self-assessed CAIQ v4 and CAIQ-Lite
The CSA questionnaire, answered in advance. Self-assessed, not audited, and titled accordingly.
QRE-GL-005QRE-GL-006Security whitepaper and architecture overview
How Pensieve is built, run and defended, written per deployment model. A control that holds in one deployment model is never claimed for another.
WPR-GL-001WPR-GL-002Software Bill of Materials
Third-party and open-source dependency disclosure, with the licence position and the patching commitment attached.
DIS-GL-019Live sub-processor register
Who processes what, where and under which model, with a change feed. Changes are announced before they take effect.
DIS-GL-009Framework mappings
SOC 2 Trust Services Criteria, CIS Controls v8, NIST CSF 2.0, GDPR Article 28, DPDP and the CERT-In Directions, each mapped to the evidence that answers it.
CHK-GL-029CHK-GL-030CHK-GL-031CHK-GL-033A published vulnerability disclosure policy
Safe harbour, acknowledgement within one business day, and named remediation targets by severity.
POL-GL-05922 documents at the public tier
The instruments themselves, versioned, hashed and dated, each carrying a review date.
Open the public tier
Committed, with dates
Each with a named owner, a target date and a published milestone list.
ISO/IEC 27001:2022 certification
No audit has commenced. The Statement of Applicability is published. The readiness statement carries the target date, the programme owner, the budget status and the milestone list. A missed date is re-dated on the record, with the reason.
STM-GL-011SOC 2, sequenced after ISO
No examination has commenced and no CPA firm is engaged. The readiness statement puts the reasoning for that sequence on the record.
STM-GL-012Independent penetration test
Not yet performed. What is published is the attestation the testing firm will sign on its own letterhead: scope, methodology, tester credentials, severity distribution, re-test and residual risk. The deliverable is fixed before the engagement is.
REP-GL-001CERT-In empanelled VAPT
Not yet performed. The safe-to-host certificate format and the release control around it are published now.
REP-GL-004Published security grades
Targets are stated in public: SSL Labs A+, Security Headers A, HSTS preload. Each is independently reproducible against this domain, and the method is published.
REP-GL-017Quarterly scan summary
SAST, SCA, container and IaC results, published on a fixed quarterly cadence.
REP-GL-016
Not held
Named in full, with the reason and the current status of each.
No ISO/IEC 27001 certificate
None held. No certification body engaged, no Stage 1 audit, no Stage 2 audit. A hospital that requires a current certificate at signature should treat that as a blocker today.
STM-GL-011No SOC 2 report, Type I or Type II
None held and none commenced. SOC 2 produces a report containing a practitioner's opinion. It does not produce a certificate, and no organisation is “SOC 2 certified”. Pensieve does not use the phrase.
STM-GL-012No HITRUST CSF certification
None held, and not on the near-term path. It is not a credential required in the markets Pensieve operates in.
No CE marking under EU MDR
Pensieve is not placed on the market as a medical device and makes no diagnostic or treatment claim.
DIS-GL-028No ARTG listing with the TGA
The same boundary, in the same document, for Australia. A hospital deploying Pensieve within a regulated clinical device workflow is the sponsor of that workflow. Pensieve is not.
DIS-GL-028No ABDM M1/M2/M3 and no NHCX participant status
Out of scope by architecture, not by omission. The hospital is the registered facility: it holds its own HFR facility ID, its clinicians hold their own HPR IDs, and it holds its own NHCX credentials. Pensieve stores them encrypted per tenant and calls those systems as the hospital, on the hospital's own authority. Pensieve is not the regulated participant and does not represent that it is.
DIS-GL-024DIS-GL-025ABDM, NHCX and the BYOK boundary
Principal documents
The 8 documents most reviews open first
Requested first by hospital security, legal and IT reviewers. Each carries a version, a content hash and a review date, and one you cannot open yet names the gate that opens it.
Accept the mutual NDA to request access to this tier. Your acceptance is recorded at once and protects both sides; an administrator then grants access, with a target of four business hours.Accept the mutual NDAWait: four business hours (target)
Accept the mutual NDA to request access to this tier. Your acceptance is recorded at once and protects both sides; an administrator then grants access, with a target of four business hours.Accept the mutual NDAWait: four business hours (target)
Accept the mutual NDA to request access to this tier. Your acceptance is recorded at once and protects both sides; an administrator then grants access, with a target of four business hours.Accept the mutual NDAWait: four business hours (target)
Accept the mutual NDA to request access to this tier. Your acceptance is recorded at once and protects both sides; an administrator then grants access, with a target of four business hours.Accept the mutual NDAWait: four business hours (target)
Accept the mutual NDA to request access to this tier. Your acceptance is recorded at once and protects both sides; an administrator then grants access, with a target of four business hours.Accept the mutual NDAWait: four business hours (target)
Accept the mutual NDA to request access to this tier. Your acceptance is recorded at once and protects both sides; an administrator then grants access, with a target of four business hours.Accept the mutual NDAWait: four business hours (target)
Accept the mutual NDA to request access to this tier. Your acceptance is recorded at once and protects both sides; an administrator then grants access, with a target of four business hours.Accept the mutual NDAWait: four business hours (target)
By reviewer
7 entry points into the same register
Each is ordered by what that reviewer opens first, and states the full count behind it.
For the hospital's IT head, CISO or security reviewer
Security
How Pensieve is built, run and defended, with the boundary of each control stated per deployment model.
- Pensieve Security WhitepaperWPR-GL-001
- Encryption DisclosureDIS-GL-011
- Authentication & Access Control DisclosureDIS-GL-012
- Audit Logging & Traceability DisclosureDIS-GL-013
- Incident Response & Breach Notification CommitmentDIS-GL-016
For the data protection officer, company secretary or compliance lead
Privacy
The DPDP position, the processing agreement, retention, deletion, data-principal rights and the grievance route: for Pensieve as processor, and for this Trust Center as a fiduciary in its own right.
- Data Processing AgreementDPA-GL-001
- Data Residency StatementDIS-GL-008
- Data Classification & Handling DisclosureDIS-GL-022
- Data Deletion & Return DisclosureDIS-GL-023
- Log Retention & Localisation DisclosureDIS-GL-034
For the hospital's advocate or external counsel
Legal
The standard paper in full: MSA, DPA, SLA, mutual NDA and the order form. Open to redline from first reading.
- Master Services Agreement (India Master)MSA-IN-001
- Data Processing AgreementDPA-GL-001
- Service Level AgreementSLA-GL-001
- Click-through Mutual Non-Disclosure AgreementNDA-GL-002
- Order Form / Commercial ScheduleORD-GL-001
For the IT lead or an external technology adviser
Architecture
What Pensieve is, how it is deployed, what it integrates with, and where Pensieve's responsibility ends in each of the four deployment models.
- Pensieve Architecture & Technical OverviewWPR-GL-002
- Deployment Models Explained (DM-1 to DM-4)WPR-GL-004
- Network & Data Flow Diagram (Sanitised)DIS-GL-006
- Interoperability & Standards DisclosureDIS-GL-029
- Uptime, Performance & Capacity DisclosureDIS-GL-030
For the hospital's IT head, CISO or data protection officer, and the external adviser they hand it to
Sovereignty
Where the data is stored, where it is processed, where the logs live, which countries a person can reach it from, and whose law can compel disclosure. Five components, one owning document each, the market fork that governs for your jurisdiction, and the tier a hospital elects if the default answer is not enough.
- Data Sovereignty Spine and Reading OrderDIS-GL-038
- Platform Sovereignty Tiers S1 to S4DIS-GL-039
- Government Access and Lawful Requests StatementSTM-GL-037
- Data Residency StatementDIS-GL-008
- Remote Access & Support Model DisclosureDIS-GL-033
For the hospital's medical director, clinical safety officer, IT head and data protection officer
AI Docs
QP is the agentic layer of the Platform, not a separate product. This hub carries what it is, what it may and may not do, who grants each level of autonomy, which models it brokers and on whose contract, where the data goes in each residency mode, and where clinical decision support stops.
- QP: What It Is, Where It Stops, and Why the Paperwork ExistsWPR-GL-700
- The QP Paperwork MapWPR-GL-702
- QP Intended Purpose Statements, One Per FunctionDIS-GL-720
- QP Autonomy Levels and the Hard InvariantsDIS-GL-702
- QP Regulatory Status and Market AvailabilityDIS-GL-718
For the hospital's IT head, service desk manager and clinical operations lead
Support
Scaffold is the support property. A hospital raises a Ticket there, tracks it there and reads the how-to library there. This hub carries what support covers and what is chargeable, who may raise a Ticket, how a severity is claimed and how it is disputed, what Pensieve may reach on a remote session and on whose consent, and where the commitments in the service level agreement stop and the mechanics begin.
- Scaffold Terms of Use, Property Charter and PrecedencePOL-GL-801
- Support Scope and Exclusions CataloguePOL-GL-804
- Severity Claiming, Confirmation and Emergency Exception ProcedurePOL-GL-806
- Service Level AgreementSLA-GL-001
- Support Policy and Escalation MatrixPOL-GL-056
Updates
The change record
Security bulletins, sub-processor changes, document revisions and the monthly overdue review list. Sub-processor changes are announced before they take effect.
Pensieve holds no security certifications, and says so
Pensieve holds no ISO 27001, no SOC 2, no HITRUST, no CE marking and no ARTG listing. The Assurance page states what exists instead, and what is in progress with dates.
The Pensieve Trust Center is live
Every formal artefact between Pensieve and a hospital customer is now published, versioned and retrievable: 108 documents with no gate at all.
Sub-processor register published with change notification
The live sub-processor register is public, and any addition is notified in advance to subscribers under NTC-GL-001.
Report a vulnerability
A defect reported to Pensieve is worth more than the same defect found by an attacker.
The disclosure policy carries safe harbour, acknowledgement within one business day, initial triage within three, and named remediation targets by severity. Critical findings are mitigated within 24 hours.
If you believe patient data is exposed, say so in the first line of the message and write to the same address. That report is handled as an incident, not as a research submission, and it is escalated on receipt.