Skip to content
DiggAIDigital Global Health Assistant InteractiveYour health information – always with you.

Documents on request

Evidence

This page collects what can be evidenced: how the data flows, what has been tested, and which documents we hand over on request. What we cannot evidence is not on this page.

1Where your data sits

Encrypted before it leaves your device

Your information is end-to-end encrypted directly on your device (X25519 key exchange, AES-256-GCM). Only the practice you selected can decrypt it again.

PatientDiggAIMedical practiceChiffratChiffratWhere your data sits
Encryption happens on the device. Only ciphertext sits on the server. Decryption happens again only at the practice.

After your practice has picked it up — after 30 days at the latest — the encrypted package is deleted from the server.

2Security reviews

Security reviews

The application was examined for security flaws in several rounds in 2026. All confirmed findings have been fixed or documented as deliberate decisions. We name no details here — a summary is available on request.

3Documents on request

Documents on request

For data protection officers, procurement and management we keep the following documents ready. Write to us and we will send them.

Technical and organisational measures (TOM)

Data processing agreement under Art. 28 GDPR

Summary of the security reviews

4What we do not claim

What we do not claim

DiggAi is not a medical device and currently holds no certification (e.g. ISO 27001). This page describes the architecture as actually built — verifiable on the live system.