Documents on request
Evidence
This page collects what can be evidenced: how the data flows, what has been tested, and which documents we hand over on request. What we cannot evidence is not on this page.
1Where your data sits
Encrypted before it leaves your device
Your information is end-to-end encrypted directly on your device (X25519 key exchange, AES-256-GCM). Only the practice you selected can decrypt it again.
After your practice has picked it up — after 30 days at the latest — the encrypted package is deleted from the server.
2Security reviews
Security reviews
The application was examined for security flaws in several rounds in 2026. All confirmed findings have been fixed or documented as deliberate decisions. We name no details here — a summary is available on request.
3Documents on request
Documents on request
For data protection officers, procurement and management we keep the following documents ready. Write to us and we will send them.
Technical and organisational measures (TOM)
Data processing agreement under Art. 28 GDPR
Summary of the security reviews
4What we do not claim
What we do not claim
DiggAi is not a medical device and currently holds no certification (e.g. ISO 27001). This page describes the architecture as actually built — verifiable on the live system.