{
  "manifest_version": "1.0",
  "generated_at": "2026-08-04T11:40:33.813Z",
  "register_generated_on": "2026-08-01",
  "canonical_url": "https://trust.pensievelabs.org/trust-manifest.json",
  "documentation": "https://trust.pensievelabs.org/llms.txt",
  "entity": {
    "legal_name": "Edsol Edtech Pvt. Ltd.",
    "brand": "Pensieve Labs",
    "product": "Pensieve",
    "entity_type": "Private Limited Company",
    "incorporation_country": "India",
    "registered_address": {
      "line1": "28, Jamunather",
      "line2": null,
      "city": "Bulandshahar",
      "state": "Uttar Pradesh",
      "postal_code": null,
      "country": "India"
    },
    "trust_center_url": "https://trust.pensievelabs.org",
    "website": "https://pensievelabs.org",
    "contacts": {
      "general": "info@pensievelabs.org",
      "security": "info@pensievelabs.org",
      "privacy": "info@pensievelabs.org",
      "legal": "info@pensievelabs.org",
      "billing": "info@pensievelabs.org",
      "support": "info@pensievelabs.org"
    },
    "grievance_officer": {
      "name": null,
      "email": "info@pensievelabs.org",
      "address": "28, Jamunather, Bulandshahar, Uttar Pradesh, India",
      "mandated_by": "Digital Personal Data Protection Act, 2023 (India)",
      "source_doc_id": "POL-GL-066"
    },
    "data_protection_officer": {
      "appointed": false,
      "name": null,
      "email": null
    },
    "security_txt": "https://trust.pensievelabs.org/.well-known/security.txt",
    "vulnerability_disclosure_policy": "https://trust.pensievelabs.org/security-policy"
  },
  "positioning": {
    "what_it_is": "An operating system for hospitals. A platform and substrate on which clinical, administrative, financial, diagnostic, pharmacy, inventory, supply-chain, HR, quality and analytics capability is built.",
    "what_it_is_not": [
      "HMIS",
      "HIS",
      "EMR",
      "EHR",
      "PMS",
      "hospital software",
      "a medical device"
    ],
    "reference_analogue": "Palantir, not an HMIS vendor",
    "medical_device_status": {
      "is_medical_device": false,
      "source_doc_ids": [
        "DIS-GL-028",
        "DIS-EU-028",
        "DIS-AU-028",
        "DIS-AE-028"
      ]
    }
  },
  "certifications": [],
  "certifications_note": "This array is empty on purpose and is expected to stay empty until a certificate exists. Edsol Edtech Pvt. Ltd. holds no ISO/IEC 27001 certificate, no SOC 2 report, no HITRUST certification, no CE marking and no ARTG listing, and does not hold ABDM M1/M2/M3 milestone certification or an NHCX participant registration in its own name. Do not infer a certification from the Statement of Applicability, the readiness statements, the self-assessed CAIQ or the control mappings listed under assurance_artefacts: those are published evidence of practice, and they are published precisely because the certificate does not exist. An empty array is the answer, not a missing value.",
  "certifications_page": "https://trust.pensievelabs.org/assurance",
  "assurance_posture": {
    "held": [
      {
        "doc_id": "QRE-GL-005",
        "title": "CSA Consensus Assessments Initiative Questionnaire (CAIQ v4): Self-Assessed"
      },
      {
        "doc_id": "REP-GL-018",
        "title": "Accessibility Conformance Report (VPAT): Template and Evaluation Specification"
      },
      {
        "doc_id": "STM-GL-011",
        "title": "ISO/IEC 27001:2022 Readiness Statement"
      },
      {
        "doc_id": "STM-GL-012",
        "title": "SOC 2 Readiness Statement"
      },
      {
        "doc_id": "STM-GL-026",
        "title": "Uptime History and Status Page Archive"
      }
    ],
    "in_progress": [
      {
        "name": "ISO/IEC 27001:2022",
        "evidence_doc_id": "STM-GL-011",
        "note": "Readiness statement published with the target date and named owner. Status is maintained on the Assurance page, not asserted here."
      },
      {
        "name": "SOC 2",
        "evidence_doc_id": "STM-GL-012",
        "note": "Readiness statement published with the target date and named owner."
      }
    ],
    "not_held": [
      {
        "name": "ISO/IEC 27001 certificate",
        "status": "not held",
        "note": "A Statement of Applicability without certification is published instead (STM-GL-010), with a readiness statement and target date (STM-GL-011)."
      },
      {
        "name": "SOC 2 Type I or Type II report",
        "status": "not held",
        "note": "A readiness statement with a target date is published instead (STM-GL-012)."
      },
      {
        "name": "HITRUST CSF certification",
        "status": "not held",
        "note": "Not on the roadmap."
      },
      {
        "name": "CE marking (EU MDR)",
        "status": "not applicable",
        "note": "Pensieve is not a medical device. The reasoning is set out in DIS-GL-028 and, for the EU, DIS-EU-028 against MDR Rule 11."
      },
      {
        "name": "ARTG listing (Australia)",
        "status": "not applicable",
        "note": "Excluded under the Therapeutic Goods Act 1989 and the Excluded Goods Determination. See DIS-AU-028."
      },
      {
        "name": "ABDM M1/M2/M3 milestone certification",
        "status": "out of scope by design",
        "note": "The hospital is the registered health facility and holds its own HFR and HPR identifiers. Pensieve integrates under BYOK/BYOC and is not the regulated participant. See DIS-GL-024 and DIS-GL-026."
      },
      {
        "name": "NHCX participant registration in Pensieve's own name",
        "status": "out of scope by design",
        "note": "The hospital holds its own NHCX participant credentials; Pensieve calls NHCX as the hospital, on the hospital's authority."
      }
    ]
  },
  "deployment_models": [
    {
      "code": "DM-1",
      "name": "Dedicated",
      "summary": "Pensieve-hosted, isolated",
      "description": "One isolated GCP project per hospital inside Edsol Edtech's organisation. Dedicated Cloud Run services, dedicated database, dedicated buckets, dedicated KMS keys.",
      "controller": "Hospital: Data Fiduciary / Controller",
      "processor": "Pensieve: Data Processor",
      "posture_statement": "Hospital = Data Fiduciary; Pensieve = Data Processor",
      "cloud_account_owner": "Edsol Edtech",
      "residency_controlled_by": "Pensieve, in the region agreed with the hospital and recorded on the deal",
      "schedule_impact": "Fastest to go-live. The default and recommended path.",
      "recommended": true,
      "supported": true
    },
    {
      "code": "DM-2",
      "name": "Shared",
      "summary": "Pensieve-hosted, multi-tenant",
      "description": "Shared platform with logical isolation by tenant, row-level security and per-tenant encryption keys.",
      "controller": "Hospital: Data Fiduciary / Controller",
      "processor": "Pensieve: Data Processor",
      "posture_statement": "Hospital = Data Fiduciary; Pensieve = Data Processor",
      "cloud_account_owner": "Edsol Edtech",
      "residency_controlled_by": "Pensieve, in the regional shared estate for the market",
      "schedule_impact": "Same schedule as DM-1. Tenant creation completes in minutes.",
      "recommended": false,
      "supported": true
    },
    {
      "code": "DM-3",
      "name": "Customer Cloud",
      "summary": "Hospital's own cloud project",
      "description": "The hospital owns and pays for the cloud project; Pensieve deploys and operates inside it under a delegated-access agreement.",
      "controller": "Hospital: Data Fiduciary / Controller, and infrastructure owner",
      "processor": "Pensieve: Data Processor with delegated administrative access under ADD-GL-009",
      "posture_statement": "Hospital = Data Fiduciary and infrastructure owner; Pensieve = Data Processor with delegated administrative access",
      "cloud_account_owner": "Hospital",
      "residency_controlled_by": "The hospital, which selects the region in its own cloud project",
      "schedule_impact": "Adds days. Requires a separate Delegated Cloud Access & Administration Agreement.",
      "recommended": false,
      "supported": true
    },
    {
      "code": "DM-4",
      "name": "On-Premise",
      "summary": "Hospital's own hardware",
      "description": "Deployed on hardware inside the hospital's own server room or private datacentre.",
      "controller": "Hospital: Data Fiduciary / Controller and full custodian",
      "processor": "Pensieve: supplier and support, with limited or no data access",
      "posture_statement": "Hospital = Data Fiduciary and full custodian; Pensieve = supplier and support, limited or no data access",
      "cloud_account_owner": "Hospital",
      "residency_controlled_by": "The hospital. The data never leaves the hospital's premises",
      "schedule_impact": "The slowest and most expensive model. It breaks the 14-day target, and Pensieve's uptime SLA cannot apply to hardware it does not control.",
      "recommended": false,
      "supported": true
    }
  ],
  "sub_processors": null,
  "sub_processors_as_at": null,
  "sub_processors_unavailable_reason": "The live register could not be read at request time. Fetch https://trust.pensievelabs.org/api/public/subprocessors, or read the published register DIS-GL-009. This field is null rather than an empty array so it is not mistaken for \"no sub-processors\".",
  "sub_processors_register_doc_id": "DIS-GL-009",
  "sub_processors_change_policy_doc_id": "POL-GL-055",
  "sub_processors_api": "https://trust.pensievelabs.org/api/public/subprocessors",
  "data_residency": {
    "claims": [
      {
        "claim": "Patient records, clinical data, prescriptions, results, images, billing and financial records are stored and processed in the deployment region and nowhere else.",
        "applies_to": [
          "DM-1",
          "DM-2",
          "DM-3",
          "DM-4"
        ],
        "source_doc_id": "DIS-GL-008"
      },
      {
        "claim": "Backups stay in the deployment region. Under DM-4 the backup media are the hospital's own, wherever the hospital keeps them.",
        "applies_to": [
          "DM-1",
          "DM-2",
          "DM-3",
          "DM-4"
        ],
        "source_doc_id": "DIS-GL-008"
      },
      {
        "claim": "System and audit logs stay in the deployment region. The CERT-In log-localisation position is stated separately.",
        "applies_to": [
          "DM-1",
          "DM-2",
          "DM-3",
          "DM-4"
        ],
        "source_doc_id": "DIS-GL-034"
      },
      {
        "claim": "Encryption keys are held in the key management service of the deployment region.",
        "applies_to": [
          "DM-1",
          "DM-2",
          "DM-3",
          "DM-4"
        ],
        "source_doc_id": "DIS-GL-011"
      },
      {
        "claim": "There is no central copy, no global data lake, no analytics extract and no training corpus of any hospital's data in any other location.",
        "applies_to": [
          "DM-1",
          "DM-2",
          "DM-3",
          "DM-4"
        ],
        "source_doc_id": "DIS-GL-008"
      },
      {
        "claim": "Human access is a separate residency component and is answered separately: the countries from which a Pensieve person can reach hospital data are named.",
        "applies_to": [
          "DM-1",
          "DM-2",
          "DM-3",
          "DM-4"
        ],
        "source_doc_id": "DIS-GL-033"
      },
      {
        "claim": "The Trust Center is a separate application holding business contact and document-access data only. It is not connected to any platform instance and holds no patient data.",
        "applies_to": [
          "DM-1",
          "DM-2",
          "DM-3",
          "DM-4"
        ],
        "source_doc_id": "DIS-GL-009"
      }
    ],
    "by_deployment_model": [
      {
        "code": "DM-1",
        "residency_controlled_by": "Pensieve, in the region agreed with the hospital and recorded on the deal"
      },
      {
        "code": "DM-2",
        "residency_controlled_by": "Pensieve, in the regional shared estate for the market"
      },
      {
        "code": "DM-3",
        "residency_controlled_by": "The hospital, which selects the region in its own cloud project"
      },
      {
        "code": "DM-4",
        "residency_controlled_by": "The hospital. The data never leaves the hospital's premises"
      }
    ],
    "default_region": "asia-south1 (Mumbai), selectable per deployment for DM-1 and DM-2",
    "source_doc_ids": [
      "DIS-GL-008",
      "DIS-GL-033",
      "DIS-GL-034"
    ],
    "market_variants": {
      "AU": "DIS-AU-008",
      "EU": "DIS-EU-008",
      "AE": "DIS-AE-008"
    }
  },
  "regulatory_boundary": {
    "abdm": {
      "pensieve_is_regulated_participant": false,
      "model": "The hospital holds its own HFR facility ID and its clinicians hold their own HPR IDs. Pensieve integrates under BYOK/BYOC and calls ABDM as the hospital, on the hospital's authority.",
      "source_doc_ids": [
        "DIS-GL-024",
        "DIS-GL-026",
        "DIS-GL-025"
      ]
    },
    "nhcx": {
      "pensieve_is_registered_participant": false,
      "model": "The hospital holds its own NHCX participant credentials. Pensieve does not onboard in its own name.",
      "source_doc_ids": [
        "DIS-GL-024",
        "DIS-GL-026"
      ]
    },
    "credential_model": "BYOK / BYOC. Credentials supplied by the hospital are stored encrypted in a per-tenant key vault, used only within the stated scope, and returned or destroyed on offboarding.",
    "credential_source_doc_ids": [
      "ADD-GL-007",
      "DIS-GL-025"
    ]
  },
  "documents": {
    "total": 491,
    "by_tier": {
      "T_CLIENT": 141,
      "T_NDA": 128,
      "T_INTERNAL": 109,
      "T_PUBLIC": 108,
      "T_EMAIL": 5
    },
    "by_kind": {
      "K_POLICY": 85,
      "K_FORM": 56,
      "K_DISCLOSURE": 49,
      "K_REGISTER": 46,
      "K_CHECKLIST": 41,
      "K_STATEMENT": 41,
      "K_CONTRACT": 39,
      "K_RUNBOOK": 33,
      "K_NOTICE": 32,
      "K_FINANCE": 22,
      "K_REPORT": 17,
      "K_CERTIFICATE": 15,
      "K_TEMPLATE": 6,
      "K_QUESTIONNAIRE": 5,
      "K_WHITEPAPER": 4
    },
    "by_jurisdiction": {
      "GL": 336,
      "IN": 105,
      "AU": 14,
      "EU": 11,
      "AE": 10,
      "NO": 8,
      "DK": 7
    },
    "by_family": {
      "1": {
        "name": "Corporate & Entity",
        "count": 40
      },
      "2": {
        "name": "Legal & Contractual",
        "count": 62
      },
      "3": {
        "name": "Security, Privacy & Trust Disclosures",
        "count": 96
      },
      "4": {
        "name": "Assurance & Evidence",
        "count": 37
      },
      "5": {
        "name": "Client Assessment & Fit",
        "count": 19
      },
      "6": {
        "name": "Hospital Input Pack",
        "count": 30
      },
      "7": {
        "name": "Runbooks",
        "count": 33
      },
      "8": {
        "name": "Checklists",
        "count": 27
      },
      "9": {
        "name": "Finance Instruments",
        "count": 28
      },
      "10": {
        "name": "Certificates & Milestones",
        "count": 15
      },
      "11": {
        "name": "Notices",
        "count": 26
      },
      "12": {
        "name": "People, Labour & Internal Governance",
        "count": 26
      },
      "13": {
        "name": "Offboarding & Exit",
        "count": 9
      },
      "14": {
        "name": "Jurisdiction Variant Sets",
        "count": 32
      },
      "15": {
        "name": "Trust Center Meta",
        "count": 11
      }
    },
    "words": 1207999,
    "public_count": 108,
    "critical_path_to_cash": 228,
    "tier_note": "Internal documents are counted here rather than concealed. Concealing the count would be the same mistake in a smaller costume."
  },
  "access_tiers": [
    {
      "code": "T_PUBLIC",
      "label": "Public: no gate",
      "count": 108,
      "gate_action": null,
      "latency": "Zero",
      "needs_human_approval": false
    },
    {
      "code": "T_EMAIL",
      "label": "Work email required",
      "count": 5,
      "gate_action": "Give a work email",
      "latency": "Zero: instant",
      "needs_human_approval": false
    },
    {
      "code": "T_NDA",
      "label": "Mutual NDA required",
      "count": 128,
      "gate_action": "Accept the mutual NDA",
      "latency": "Target 4 business hours",
      "needs_human_approval": true
    },
    {
      "code": "T_CLIENT",
      "label": "Client credential required",
      "count": 141,
      "gate_action": "Sign in to your workspace",
      "latency": "Target 4 business hours",
      "needs_human_approval": true
    },
    {
      "code": "T_INTERNAL",
      "label": "Pensieve internal",
      "count": 109,
      "gate_action": "Administrator access only",
      "latency": "n/a",
      "needs_human_approval": false
    }
  ],
  "assurance_artefacts": [
    {
      "doc_id": "QRE-GL-005",
      "title": "CSA Consensus Assessments Initiative Questionnaire (CAIQ v4): Self-Assessed",
      "kind": "K_QUESTIONNAIRE",
      "tier": "T_PUBLIC",
      "semver": "1.0.0",
      "last_modified_on": "2026-07-31",
      "review_due_on": "2027-07-31",
      "sha256": "ca18ba584949261c1bf9b5efd9c40c6c4f84049e368ce7929e1815b2990c20b0",
      "url": "https://trust.pensievelabs.org/documents/qre-gl-005-csa-consensus-assessments-initiative-questionnaire-caiq-v4-self",
      "api_url": "https://trust.pensievelabs.org/api/public/documents/qre-gl-005-csa-consensus-assessments-initiative-questionnaire-caiq-v4-self",
      "verify_url": "https://trust.pensievelabs.org/verify/CA18BA584949"
    },
    {
      "doc_id": "REP-GL-018",
      "title": "Accessibility Conformance Report (VPAT): Template and Evaluation Specification",
      "kind": "K_REPORT",
      "tier": "T_PUBLIC",
      "semver": "1.0.0",
      "last_modified_on": "2026-08-01",
      "review_due_on": "2027-01-31",
      "sha256": "55c7817961fdb848d6e8a0fb9d161baabb7c9cefc9656a027984d0f5ffa1ebae",
      "url": "https://trust.pensievelabs.org/documents/rep-gl-018-accessibility-conformance-report-vpat-template-and-evaluation",
      "api_url": "https://trust.pensievelabs.org/api/public/documents/rep-gl-018-accessibility-conformance-report-vpat-template-and-evaluation",
      "verify_url": "https://trust.pensievelabs.org/verify/55C7817961FD"
    },
    {
      "doc_id": "STM-GL-011",
      "title": "ISO/IEC 27001:2022 Readiness Statement",
      "kind": "K_STATEMENT",
      "tier": "T_PUBLIC",
      "semver": "1.0.0",
      "last_modified_on": "2026-07-31",
      "review_due_on": "2026-10-31",
      "sha256": "0e5dd18ae24e118195ad7b6713bbc7bbea7ef18dc1026341058ca40941f0935d",
      "url": "https://trust.pensievelabs.org/documents/stm-gl-011-iso-iec-27001-2022-readiness-statement",
      "api_url": "https://trust.pensievelabs.org/api/public/documents/stm-gl-011-iso-iec-27001-2022-readiness-statement",
      "verify_url": "https://trust.pensievelabs.org/verify/0E5DD18AE24E"
    },
    {
      "doc_id": "STM-GL-012",
      "title": "SOC 2 Readiness Statement",
      "kind": "K_STATEMENT",
      "tier": "T_PUBLIC",
      "semver": "1.0.0",
      "last_modified_on": "2026-07-31",
      "review_due_on": "2026-10-31",
      "sha256": "33934be67b47444b8168f1c4ea8fc0fb054a225422b260b7b9c8654e9e9c06a1",
      "url": "https://trust.pensievelabs.org/documents/stm-gl-012-soc-2-readiness-statement",
      "api_url": "https://trust.pensievelabs.org/api/public/documents/stm-gl-012-soc-2-readiness-statement",
      "verify_url": "https://trust.pensievelabs.org/verify/33934BE67B47"
    },
    {
      "doc_id": "STM-GL-026",
      "title": "Uptime History and Status Page Archive",
      "kind": "K_STATEMENT",
      "tier": "T_PUBLIC",
      "semver": "1.0.0",
      "last_modified_on": "2026-08-01",
      "review_due_on": "2027-01-31",
      "sha256": "b9fa5b1c4aa6f45f510bc083d72dbeec29c865cb757177725a0614ab84693c69",
      "url": "https://trust.pensievelabs.org/documents/stm-gl-026-uptime-history-and-status-page-archive",
      "api_url": "https://trust.pensievelabs.org/api/public/documents/stm-gl-026-uptime-history-and-status-page-archive",
      "verify_url": "https://trust.pensievelabs.org/verify/B9FA5B1C4AA6"
    }
  ],
  "jurisdictions": [
    {
      "code": "GL",
      "name": "Global",
      "document_count": 336,
      "page": null
    },
    {
      "code": "IN",
      "name": "India",
      "document_count": 105,
      "page": "https://trust.pensievelabs.org/jurisdictions/in"
    },
    {
      "code": "AU",
      "name": "Australia",
      "document_count": 14,
      "page": "https://trust.pensievelabs.org/jurisdictions/au"
    },
    {
      "code": "EU",
      "name": "EU / EEA",
      "document_count": 11,
      "page": "https://trust.pensievelabs.org/jurisdictions/eu"
    },
    {
      "code": "DK",
      "name": "Denmark",
      "document_count": 7,
      "page": "https://trust.pensievelabs.org/jurisdictions/dk"
    },
    {
      "code": "NO",
      "name": "Norway",
      "document_count": 8,
      "page": "https://trust.pensievelabs.org/jurisdictions/no"
    },
    {
      "code": "AE",
      "name": "United Arab Emirates",
      "document_count": 10,
      "page": "https://trust.pensievelabs.org/jurisdictions/ae"
    }
  ],
  "verification": {
    "verify_base_url": "https://trust.pensievelabs.org/verify/",
    "method": "SHA-256 of the document body. The first twelve hexadecimal characters, upper-cased, are the short form printed on every rendered document and accepted by the verify route.",
    "note": "A hash that does not resolve means the text you are holding is not a current Pensieve document."
  },
  "api": {
    "documents": "https://trust.pensievelabs.org/api/public/documents",
    "document": "https://trust.pensievelabs.org/api/public/documents/{slug}",
    "subprocessors": "https://trust.pensievelabs.org/api/public/subprocessors",
    "updates": "https://trust.pensievelabs.org/api/public/updates",
    "policies": "https://trust.pensievelabs.org/api/public/policies/{slug}",
    "evidence_pack": "https://trust.pensievelabs.org/api/evidence-pack?tier=public",
    "llms_txt": "https://trust.pensievelabs.org/llms.txt",
    "rss": "https://trust.pensievelabs.org/updates.rss",
    "sitemap": "https://trust.pensievelabs.org/sitemap.xml",
    "security_txt": "https://trust.pensievelabs.org/.well-known/security.txt",
    "cors": "GET only, Access-Control-Allow-Origin: *. The marketing site renders these and keeps no copy of its own."
  },
  "trust_center_itself": {
    "hosting": [
      "Vercel (application)",
      "Neon (Postgres)"
    ],
    "third_party_scripts": 0,
    "third_party_analytics": false,
    "external_fonts": false,
    "note": "First-party analytics only, stored in this application's own database. A trust center that ships its visitors to a third-party analytics vendor is arguing against itself. Verifiable from the network tab."
  }
}