Trust
Trust
Everything in this section is written to be checked rather than believed. Where a control exists we say how it is enforced; where one does not, we say that too.
Healthcare buyers are right to be sceptical of vendor security pages, because most of them are written to survive a skim rather than a question. These pages take the opposite approach: each control is described at the level a reviewer could test, and the gaps are published alongside the strengths.
The invariant worth knowing before anything else: Rydya stores no patient clinical records at all. That is a product boundary rather than a setting, and it limits what a breach of Rydya could ever expose.
Security
Security pages usually list what a vendor has. This one also lists what we have not done, because you are going to find out either way, and the second list tells you more about us than the first. Everything here is something an engineer could be asked to demonstrate rather than describe.
Tenant isolation
This is the control that matters most and the one most often described in a way that cannot be checked. Isolation in Rydya is not a filter the application remembers to apply. It is a property of the database, enforced below the code, and there is a structural audit that fails the build rather than a paragraph asking you to trust us.
Authentication
Authentication answers one question: are you who you claim to be. It is not the same as authorisation, which asks what you may then do, and conflating the two is how products end up with strong logins and weak boundaries. This page covers the first. The permissions page covers the second.
Encryption
Encryption is the security claim most often inflated and most easily checked, which is a bad combination for a vendor and a useful one for you. This page draws the lines exactly: what the platform underneath us provides, what we build ourselves, and what we do not have. The third list is the shortest and the most important.
Backups and recovery
Until a restore has actually been performed, a backup is a belief rather than a capability. We have not performed one. That sentence is the whole page, and everything below explains what we do have, what we will not claim, and what would have to be true before we could.
Data protection
Most data-protection pages are a legal document wearing a marketing layout. This one is an inventory instead: what data actually exists in Rydya, what the product does with it, and where the answer is that nobody has decided yet. The legal interpretation is not ours to give and we are not going to pretend otherwise.
Responsible AI
The responsible position on AI, for a product that helps decide whether medical equipment is safe to use, turned out to be not having any. There is no model in Rydya, no inference, and no AI vendor in the path of any decision. This page explains that choice, and what would have to be true before it changed.