Pensieve holds no security certifications, and says so
A change to what Pensieve holds, claims, publishes or has stopped claiming. Certification positions live here.
Summary
Pensieve holds no ISO 27001, no SOC 2, no HITRUST, no CE marking and no ARTG listing. The Assurance page states what exists instead, and what is in progress with dates.
Background
Buyers discover certification gaps anyway. Discovering them from the vendor first is disarming, and it removes the discovery from the security review, which removes days.
Details
What exists today: an ISO 27001 Statement of Applicability without certification, a self-assessed CAIQ, published policies, an SBOM, and the security grades for this site. What is deliberately out of scope: ABDM M1/M2/M3 and NHCX certification. Pensieve integrates using the hospital's own credentials under a BYOK/BYOC model and is not the regulated participant.
Remediation
Read the Assurance page and the Integration Boundary Statement.