Trust, shown not asserted
Security and compliance
OxRad keeps patient imaging data on-site and lets you prove what happened to it. The mechanisms below are engineering, not promises.
How does OxRad keep medical imaging data secure?
OxRad keeps patient imaging data on-site and proves what happened to it. Inference runs on the OxRad on-site node, a tamper-evident audit records every action, and the OxRad Protocol supports privacy-preserving improvement across sites without raw scans ever leaving a site.
Tamper-evident audit (OxChain)
Trust in medical AI should be verifiable, not requested. OxChain is OxRad’s tamper-evident audit layer: every access, inference, edit, and export is written to an append-only record that cannot be altered after the fact. Each entry is cryptographically chained to the one before it, so any attempt to change history is immediately detectable.
The point is demonstrability. Rather than asking you to believe a cloud vendor’s internal logs, OxRad gives you a record you can inspect yourself: what study was read, by which process, when, and where the resulting report went. For a clinic answering to regulators, insurers, or patients, that is the difference between a promise and proof.
Mathematically safeguarded improvement
OxRad gets better the more it is used, without any site giving up its data. Improvement across sites is privacy-preserving by design: raw scans never leave the premises where they were created, and patient imaging is never pooled in a central place to make the system smarter.
Anything shared between sites is mathematically safeguarded, so it cannot be traced back to any individual record. The safeguards are built into the process, not left as a setting a busy site might forget to enable, and we do not detail the internal design publicly.
That is the opposite of the usual bargain. Conventional cloud AI asks you to centralise data so a model can improve. OxRad keeps every study inside its own walls and still contributes to a system that improves over time.
The OxRad Protocol
The OxRad Protocol is designed to support privacy-preserving improvement across sites without raw scans leaving any site. Each OxRad on-site node contributes only protected updates; the patient imaging stays on the premises where it was created.
The full method, including how those updates are protected, is set out in the OxRad Build Paper, shared with serious partners under NDA.
Data residency
Data residency is simple when data does not move. Patient imaging is processed on the OxRad on-site node, inside your premises and your jurisdiction. Inference is local, the drafted report is produced locally, and nothing transits the cloud at any step.
For jurisdictions with data-localisation rules, or any organisation that simply does not want patient scans leaving the country, this removes the hardest problem at the root. There is no cross-border transfer to justify, no third-party region to vet, and no off-site copy to account for. The data stays where the law, and the patient, expects it to be.
Regulatory roadmap
The standards and approvals below are targets in progress, not held certifications. OxRad is positioned as reporting-assist with human sign-off, and we state the pathway openly rather than imply approvals we do not yet hold.
- UKCATarget
UK medical device marking
- CDSCOTarget
Medical device approval pathway
- HL7 FHIRTarget
Health data interoperability
- DICOM 3.0Target
Imaging interchange standard
- ISO 13485Target
Medical device quality management
Common questions
- How can a radiology AI prove it did not leak patient data?
- Through a tamper-evident audit. OxChain records every access, inference, and export to an append-only log that cannot be altered after the fact. You can inspect exactly what happened to a study rather than take a vendor's word for it.
- How does OxRad improve across sites without moving patient scans?
- Through the OxRad Protocol. It is designed to support privacy-preserving improvement across sites, with raw scans never leaving the premises where they were created. The full method is documented in the OxRad Build Paper, shared with serious partners under NDA.
- How are the updates shared between sites protected?
- Anything shared between OxRad sites is mathematically safeguarded so it cannot be traced back to any individual record. Improving the system never comes at the cost of a patient's privacy, and raw imaging never leaves the site.
- Where does the patient data live?
- On the OxRad on-site node, inside your premises and your jurisdiction. Inference is local and nothing transits the cloud, which supports data-residency and localisation requirements.
Evaluate on-site AI reporting that keeps patient data on your premises.
We are taking a small number of pilot partners.