Search all 478 artefacts by title, document ID or content.
Printed on the standard letterhead. Page furniture, margins and repeating table headers come from the same stylesheet the PDF service uses.
Pensieve Labs
The operating system for hospitals
POL-IN-305
v1.0.0 | 31 July 2026
The standard of behaviour required of every person acting for Edsol Edtech Pvt. Ltd.. It is short on
principle and specific on the things that actually go wrong in a company that builds software hospitals run
on.
Every employee, contractor, intern, director and adviser, at all times when acting for the Company, on customer premises, and when identifiable as connected with the Company.
1.1 Patient information is not yours to look at. You access a patient record only when a specific work
task requires it, only to the extent that task requires, and never out of curiosity: not your own record,
not a relative's, not a colleague's, not a public figure's. Every access is logged and attributable. This
is the rule most likely to end an employment at Edsol Edtech Pvt. Ltd., and the one hospitals ask about
first.
1.2 Never impede clinical care. If a decision you can make would degrade a hospital's ability to treat
a patient, escalate rather than decide. When in doubt, keep the hospital running and sort out the commercial
or technical consequence afterwards. MSA-IN-001 clause 20.4 is a contractual expression of this rule; it
is also simply the rule.
1.3 Tell the truth about the product. Do not claim a certification the Company does not hold, a
customer it does not have, a capability it has not built, or a metric it has not measured.
Edsol Edtech Pvt. Ltd. holds no ISO/IEC 27001, SOC 2 or HITRUST certification and no CE or ARTG
registration, and no person may say or imply otherwise. Say what is true and say what compensates.
1.4 No bribes, no facilitation payments, no exceptions. STM-GL-030 is the Company's declaration and
it binds you. This includes payments to secure a tender, an inspection outcome, a licence, a registration, a
faster clearance, or a referral. A demand for one is reported to the Founder the same day and is not paid,
whatever the commercial consequence.
1.5 Gifts and hospitality. Nothing of more than nominal value may be given to or accepted from a person connected with a customer, a prospect, a supplier, a regulator or a public official. Nothing at all during a live procurement or tender. Anything received that cannot be declined is declared to the Founder and recorded. Referral fees, commissions and kickbacks to a hospital's employee are never paid.
1.6 No clinical advice. Pensieve is not a medical device and you do not give clinical
advice, interpret a result, or suggest a treatment, whatever your qualification and however helpful it
would be in the moment. DIS-GL-028 is the boundary and it is a regulatory exposure, not a style
preference.
1.7 Conflicts of interest are declared, not managed privately. A financial interest in a customer,
prospect, supplier or competitor; a close relative in a decision-making role at one; outside work that
overlaps with the Company's business. Declare it on STM-IN-017 and let it be decided.
1.8 Respect at work, and on a hospital's premises. Harassment, discrimination, bullying and retaliation
are prohibited. POL-IN-306 and POL-IN-307 apply. On a hospital's premises you are a guest in a place
where people are frightened and unwell. POL-IN-318 states what that requires of you.
1.9 Company property and information. Use Company systems for Company work; do not install unapproved software; do not move Company or customer information onto personal accounts or devices; do not share credentials; do not work around a control because it is inconvenient. Report a control you cannot work with so it can be fixed.
1.10 Speak up. If something looks wrong, a security shortcut, a misleading claim, a payment you do not
understand, a colleague's behaviour, your own error, report it under POL-IN-308. Reporting in good
faith is protected, including where you report your own mistake, and retaliation is itself a disciplinary
offence.
1.11 Accurate records. Time, expenses, test results, incident timelines, log entries and evidence for a customer's audit are recorded accurately. Never backdate anything.
1.12 Competition and the market. Compete on the product. Do not disparage a competitor, do not use a competitor's confidential information, do not induce a hospital to breach an existing contract, and do not discuss pricing or market allocation with a competitor.
1.13 Public statements. Only the Founder speaks for Edsol Edtech Pvt. Ltd. publicly. Do not post about
a customer, an incident, an outage, an unreleased feature or a commercial negotiation. Never post a
screenshot containing customer data, including a screenshot you believe is anonymised.
1.14 Insider information and confidentiality after you leave. POL-IN-302 continues to bind you
without limit of time.
2.1 The test, when the Code does not answer the question. Would you be comfortable if the hospital's medical director, the patient concerned, and a journalist all saw exactly what you did and why? If not, do not do it, and ask.
2.2 Where to ask. Your manager, the Founder, or info@pensievelabs.org. Asking first is
always a defence; not asking is not.
2.3 Breach. Handled under POL-GL-322. A breach of Section 1.1, Section 1.4 or Section 1.13 is treated as gross misconduct.
A breach that is disclosed by the person who committed it is treated more leniently than one discovered,
and that difference is deliberate and is honoured.
2.4 Acknowledgement. Every person acknowledges this Code on joining and annually thereafter; the record
is kept in the Training Register (REG-GL-209).
2.5 Reporting to hospitals. Where a breach of this Code affected a hospital, that hospital is told,
under NTC-GL-002 if it was a security or data matter, and directly by the Founder otherwise. The
Company does not manage a conduct failure that touched a customer as an internal matter.
| Topic | Document |
|---|---|
| What hospitals are told about personnel controls | DIS-GL-020 |
| Confidentiality and IP | POL-IN-302 |
| POSH | POL-IN-306 |
| Equal opportunity | POL-IN-307 |
| Whistleblower and grievance | POL-IN-308 |
| On-site conduct at a hospital | POL-IN-318 |
| Joiner-mover-leaver | POL-GL-321 |
| Disciplinary procedure | POL-GL-322 |
| Anti-bribery declaration | STM-GL-030 |
| Conflict of interest declaration | STM-IN-017 |
| Clinical safety boundary | DIS-GL-028 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 31 July 2026 |
Founder | First publication. Three verification levels keyed to access rather than seniority, with an explicit list of what is not checked; adverse findings answered by the person before any decision; six-month deletion for unsuccessful candidates; Code of Conduct leading with the patient-record rule, the no-certification-claim rule and the never-impede-clinical-care rule, and requiring a hospital to be told when a conduct failure touched it. |