Assurance and evidence
What we have, what is coming, and what we do not have
Edsol Edtech Pvt. Ltd. holds no security certifications. No ISO/IEC 27001. No SOC 2. No HITRUST. No CE marking. No ARTG listing. No ABDM milestone certification.
That sentence is on the first screen rather than in a footnote, because a hospital that finds it in a footnote will reasonably wonder what else is in a footnote. Everything below says what exists instead, what is being built, and what is simply missing, with the document that evidences each line.
Why the third column exists
Most vendors publish the first column. Some publish the second. The third one is here for a commercial reason rather than a moral one.
A buyer discovers a gap anyway. The only variable is when, and from whom. A gap your own reviewer finds in week three is a finding: it goes into a report, it acquires an owner, it generates a follow-up meeting and a clarification email, and it costs days. The same gap disclosed by the vendor in week zero is a fact your reviewer records and moves past, because there is nothing left to discover. Publishing what is missing removes the discovery from the security review, and removing the discovery removes the days.
There is a second effect and it is the one that decides deals. An unknown supplier asking a hospital to run its entire operation (clinical, financial, pharmacy, stores, HR) cannot survive a single discovered overstatement. The incentive to be accurate is therefore stronger than the incentive to look impressive. That is arithmetic, not character, and it is the reason the third column is longer than the second.
This page is a reading of the Trust & Assurance Overview, which is the authoritative register of what assurance exists. Where the two disagree, that document is correct and this page is a defect. Report it to info@pensievelabs.org.
The three columns
Column 1
What we have today
Checkable now, before you speak to anyone.
- Independent penetration test: attestation instrument
- CERT-In empanelled VAPT: report specification and Safe-to-Host form
- Self-assessed CAIQ v4, in full
- ISO/IEC 27001:2022 Statement of Applicability, uncertified
- 38 published policies, ungated
- Software bill of materials, per release
- Cyber liability and technology E&O insurance
- Source-code escrow, tri-party
- Security grades for this site
Column 2
What we are doing next
Two programmes. Each with an owner role and a public status.
- ISO/IEC 27001:2022 certification: not commenced
- SOC 2 Type I examination: not commenced
- Target dates: [TO BE SUPPLIED]
Column 3
What we do not have
The longest column, deliberately.
- ISO/IEC 27001 certificate
- SOC 2 report, Type I or Type II
- HITRUST: decided against, on the record
- CE marking
- ARTG listing
- ABDM M1/M2/M3: deliberately out of scope
Section 1
Held today, item by item
Each row states what the instrument is, its class, and its status as at today’s date. Where a published instrument is a specification or a template awaiting an engagement, the row says so rather than implying an engagement has happened.
| Instrument | Class | Status as at today | Evidence |
|---|---|---|---|
| Independent penetration test attestation | ATT | The attestation letter the testing firm signs, and the release control governing what may be published from a full report, are both published. No external offensive-security engagement has been completed, so no attestation has been issued yet. The engagement is item 1 of the programme below. | |
| CERT-In empanelled VAPT | ATT | The audit specification, the release control and the Safe-to-Host certificate form are published. No audit by an empanelled auditing organisation has been completed. This is the most locally authoritative credential available in India and it is the first item of the programme. | |
| Self-assessed CAIQ v4 | SELF | Completed and published in full, together with the CAIQ-Lite form. It is self-assessed and says so on its face; no third party has reviewed it. Its value is that it removes the security-questionnaire round trip and can be read by anyone, in any country, with no NDA. | |
| ISO/IEC 27001:2022 Statement of Applicability, without certification | SELF | Published in full across all 93 Annex A controls: 57 of the 90 applicable controls implemented, 21 partial, 3 not implemented, 9 inherited from the cloud provider. It is published as a gap list rather than a claim list. No certification body has audited it and it is not a certificate. | |
| The published policy set | SELF | 38 policies published with no gate at all, out of 85 in the register: information security, access control, cryptography, key management, logging, incident response, backup, change management, secure development, privileged access, break-glass and sub-processor management, each with a named owner role and a review cadence. The remainder are internal governance documents about how Pensieve Labs runs itself. | |
| Software bill of materials | SELF | CycloneDX and SPDX, produced per release, with the third-party and open-source dependency disclosure and the static-analysis and dependency-scan summary. Machine-checkable, so a hospital can determine in minutes whether a newly announced library vulnerability affects it. | |
| Cyber liability and technology errors & omissions insurance | Third-party instrument | The certificate is published at the NDA tier: the existence and status of cover are public, the policy limits are not, because a published limit tells a claimant what a claim is worth. Where a cover line is not yet bound, the certificate states that rather than implying otherwise, and binding cover is frequently made a condition precedent on the Order Form. | |
| Source-code escrow | Third-party instrument | A tri-party escrow with an independent agent, with beneficiary accession by joinder so that a hospital becomes a beneficiary without a fresh tripartite negotiation. Deposit cadence, release events and the licence on release are all published. Customer data is not deposited: it is not Pensieve's to deposit. | |
| Security grades for this site | Independent, reproducible | The only assurance artefact here that a third party generates and anybody can re-run at any moment, without Pensieve's cooperation. The targets are published; the current grades are not yet populated. See the table in Section 4, and run the scan yourself. |
Those nine sit on a wider published surface: the security whitepaper with its per-model treatment and its section listing what is not implemented (WPR-GL-001), the sanitised architecture and data-flow diagrams (DIS-GL-006), the sub-processor register (DIS-GL-009) and the whole contract stack published before anybody asks for it: MSA-IN-001, DPA-GL-001 and SLA-GL-001. A published standard contract cannot be quietly weaker for the next hospital, and your advocate can read it before the first meeting.
Section 2
In progress, with an owner and a public status
Two programmes, in this order. ISO/IEC 27001 first, because the management system produces the control environment, the evidence repository and the policy set a SOC 2 readiness phase would otherwise build from scratch, and because ISO is the credential Pensieve Labs’s actual markets ask for.
| Programme | Class | Owner role | Named owner | Public status today | Target date |
|---|---|---|---|---|---|
| ISO/IEC 27001:2022 certificationWith ISO/IEC 27017 and 27018 as extensions in the same scope. All four deployment models in scope; the corporate office in scope. | CERT | Security | [TO BE SUPPLIED] | Not commenced. No certification body engaged. No Stage 1 or Stage 2 audit has taken place. The Statement of Applicability is published. Pensieve Labs will not accept a certificate from a body that is not accredited by an IAF-recognised accreditation body, and neither should you, from any vendor. | [TO BE SUPPLIED] |
| SOC 2 Type I examinationSecurity, Availability and Confidentiality. Processing Integrity and Privacy are not in the intended initial scope. Type II and a publishable SOC 3 follow. | ATT | Security | [TO BE SUPPLIED] | Not commenced.No CPA firm engaged. The Trust Services Criteria control mapping is published. SOC 2 produces a report containing a practitioner’s opinion. It does not produce a certificate, and no organisation is “SOC 2 certified”. | [TO BE SUPPLIED] |
What Pensieve Labs commits to about this table
- No date is invented. [TO BE SUPPLIED] is what an unset target looks like. It is not a placeholder for a date Pensieve Labsknows and is withholding, and it is not a soft way of saying “soon”. A date appears here when it is a decision with a budget behind it.
- Dates are published so they can be missed in public. A slipped target is re-dated here with the reason and the previous target left visible. It is never quietly deleted.
- Owners are named individuals, not departments. The owner role is recorded in the register today; the named owner is published when the programme is funded. A credential owned by “the team” is a credential nobody is delivering.
- A certification project will never delay a publication. The order is publish, sell, then certify with the revenue, because a hospital’s decision is made in days and a certificate arrives in months.
- An in-progress item is never described as held. Nothing moves from column 3 to column 1 until the underlying artefact exists and is published or produceable on request.
Section 3
Not held
Two of the rows below will never move. They are not backlog items that have been deprioritised; they are decisions, and publishing them is the point: a roadmap that contains everything contains nothing.
| Not held | What that means for you | Planned? | Evidence |
|---|---|---|---|
| ISO/IEC 27001 certificate | No accredited certification body has assessed Pensieve's information security management system. The Statement of Applicability published in column 1 is a self-assessment and must not be presented as a certificate by anybody, including Pensieve. | Yes (Section 2) | |
| SOC 2 report (Type I or Type II) | No licensed practitioner has opined on the design of Pensieve's controls or on their operating effectiveness over a period. There is no report to send you under NDA, because there is no report. | Yes: Type I first, then Type II, then a publishable SOC 3 | |
| HITRUST, in any tier | A United States health-plan and health-system vendor artefact driven by US-specific contractual requirements. No Indian, Australian, Danish, Norwegian or Emirati hospital procurement asks for it. Pursuing it would consume more cash than Pensieve's entire certification programme and would unlock nothing. | No. Decided against, on the record. Revisited only if a United States buyer appears. | |
| CE marking | Pensieve is deliberately outside the software-as-a-medical-device boundary: it does not diagnose, triage, score clinical risk, calculate patient-specific doses or recommend treatment. There is therefore nothing to mark. The corollary is stated rather than hidden: this position permanently constrains what Pensieve can become. | No. Buying device conformity would be an implicit assertion that Pensieve is a device. | |
| ARTG listing | Pensieve is not included on the Australian Register of Therapeutic Goods, for the same reason as CE marking. The Australian clinical safety boundary statement sets out the position against the Therapeutic Goods Act and the excluded goods determination. | No, on the same basis. | |
| ABDM M1 / M2 / M3 milestone certification | Deliberately out of scope.The hospital is the registered health facility, holds its own HFR facility identifier, its clinicians hold their own HPR identifiers, and it holds its own NHCX participant credentials. Pensieve integrates on the hospital’s own credentials and calls those systems as the hospital. It is therefore not the regulated participant and does not represent that it is. This is an architectural boundary, not a gap, and it is the one item on this page that can affect a go-live date, so read the boundary in full before you commit to any ABDM or NHCX obligation. | No, and not on any roadmap. If your state or scheme requires that the software itself be certified, Pensieve does not satisfy that requirement. Check it at qualification, not at cutover. |
Operational limitations, restated
These are in the security whitepaper too, but a hospital reading only this page should still see them.
- No independent audit of the controls described in the security whitepaper.
- No 24×7 staffed security operations centre. Monitoring is continuous and alerts route to an on-call engineer; there is no staffed watch floor.
- Limited separation of duties. At Edsol Edtech Pvt. Ltd.’s size the same small group builds and operates the platform. The compensating controls are mandatory peer review, second-person approval for production access, and immutable audit logs the accessing engineer cannot alter.
- In DM-1 and DM-2, Pensieve can technically decrypt hospital data through an approved, time-bound, logged path. There is no customer-held-key architecture in the hosted models. A hospital that requires a structural rather than procedural control should choose DM-3 or DM-4. See the deployment models.
- DM-2 isolation is logical, in four layers. It is not equivalent to DM-1.
- No availability commitment for DM-4, and no RTO or RPO commitment for infrastructure Pensieve does not control.
- No customer references yet. Pensieve Labs does not publish a customer list, logos or reference letters, because it does not yet have consented references to publish. Treat that as a real risk and price it: ask to speak to the engineering team rather than to a reference, and ask for first-customer terms.
Section 4
Security grades for this site
Free, same-day and independently reproducible. Every grade below can be re-run by any reader against a public scanner, without Edsol Edtech Pvt. Ltd.’s cooperation, in under five minutes. That is the entire point of publishing it. It is the only assurance artefact here that you can verify before you have spoken to anyone.
These grades prove nothing about the platform’s internals. They prove that the basics were not skipped, and their absence proves the opposite. The targets below are committed; the current grades are populated on the first scoring run and are re-scored quarterly and same-day after any ingress change. In DM-4 they cover nothing at all, because the ingress belongs to the hospital.
| Assessment | Target | Current | Reproduce it yourself |
|---|---|---|---|
| TLS configuration: Qualys SSL Labs | A+ | [TO BE SUPPLIED] | Run the public SSL Labs server test against this host. |
| HTTP response headers: Security Headers | A | [TO BE SUPPLIED] | Run the public Security Headers scan against this host. |
| Header and TLS posture: MDN HTTP Observatory | A | [TO BE SUPPLIED] | Run the Mozilla Observatory scan. |
| HSTS preload status | Preloaded | [TO BE SUPPLIED] | Query the browser preload list for the domain. Landing takes months, because entries are compiled into browser source. |
| Vulnerability disclosure: security.txt | Present and unexpired | Published | Fetch /.well-known/security.txt. An expired file is a public signal of neglect and is the first thing a reviewer checks. |
| Email authentication: SPF, DKIM, DMARC | DMARC at enforcement | [TO BE SUPPLIED] | Query the _dmarc record for the sending domain. |
Third-party rating agencies rate organisations whether or not they ask to be rated. Pensieve Labsdoes not purchase a rating and does not publish one. Where a hospital’s procurement relies on such a score, Pensieve Labs will discuss the specific findings rather than the letter. The snapshot itself is REP-GL-017; this Trust Center loads no third-party script, no analytics tag and no external font, which you are invited to verify in your network tab.
Section 5
The sentences Pensieve will not say
This table binds every Pensieve Labs document, proposal, questionnaire response, sales conversation and web page. It is published so that you can hold Pensieve Labs to it, and so that you can apply the same test to every other vendor in your evaluation.
| Pensieve Labs will never say | Pensieve Labs says instead |
|---|---|
| “We are ISO 27001 compliant” | Pensieve Labs operates an information security management system aligned to ISO/IEC 27001:2022. Edsol Edtech Pvt. Ltd. is not certified. The Statement of Applicability is published. |
| “We are CERT-In certified” | The platform was audited by a CERT-In empanelled information security auditing organisation. The attestation letter and the Safe-to-Host certificate are published; the full report is available under NDA. (This sentence becomes available only once the audit is complete.) |
| “We are MeitY empanelled” | Pensieve runs on Google Cloud in the India regions, which are MeitY-empanelled following an STQC audit. Empanelment applies to the cloud infrastructure, not to the Pensieve application. |
| “We are ABDM certified” | Pensieve Labs is not ABDM-certified and does not seek milestone certification. The hospital is the registered facility and holds its own credentials; Pensieve integrates on the hospital's authority. |
| “SOC 2 certified” | SOC 2 produces a report, not a certificate. Nobody is SOC 2 certified. A vendor that says otherwise has not read its own report. |
| “Bank-grade security, military-grade encryption” | The algorithm, the key length, the key management service and the rotation period, by name, in the encryption disclosure. |
| “99.99% uptime, as a bare figure” | The availability commitment with its measurement method, its exclusions and the deployment models it applies to, in the Service Level Agreement. |
| “Your data is fully isolated (of DM-2)” | DM-2 isolation is logical, in four layers, and it is not equivalent to DM-1. |
If you ever receive a Pensieve Labs document, proposal or email containing a sentence from the left column, it is wrong. Send it to info@pensievelabs.org and it will be corrected, and the correction recorded.
Section 6
How this page is kept honest
| Mechanism | Detail |
|---|---|
| Review cadence | Quarterly, or immediately on any change of status. The review date drives an internal staleness alert, and a document past its review date is flagged in public on its own row. |
| Published dates | Every artefact linked from this page carries its last-modified date on its own page. A stale date is visible to you rather than hidden from you. |
| Slipped targets | Re-dated with a reason, with the previous target left in the change history. Targets are not deleted. |
| Correction channel | Any reader who finds a statement in any Pensieve Labs document that is inaccurate can report it to info@pensievelabs.org, and the correction is recorded. |
| Precedence | Where this page and any other Pensieve Labs artefact disagree about what assurance exists, WPR-GL-005 is correct. |
| Why /compliance lands here | Buyers type /compliance, so that address resolves to this page. There is no compliance section in the Palantir sense, because there is nothing certified to display in one. |
The most useful thing you can do with this page is take it into meetings with every other vendor you are evaluating. Pensieve Labs is content to be judged by the same standard.