Clinical security & AI

Assistive AI. Not decisive.

Technology organizes the signal. The clinical team interprets, decides and acts.

What AI does and what it doesn't.

AI does

  • Summarises what the patient already logged, to prepare each session
  • Drafts descriptive summaries the professional reviews and approves
  • Retrieves and quotes the record verbatim, with date and source
  • Helps moderate the community, always with human review

AI does not

  • Does not issue diagnoses or clinical assessments
  • Does not score, classify or predict
  • Does not make decisions or act without human supervision
  • Does not receive identities: information is anonymised before being sent

Privacy by design

Security from the code.

Role-based access

Each profile sees only what the protocol allows. No exceptions.

Data minimization

Only what's needed for clinical follow-up is collected.

Full audit trail

Immutable record of who accessed what and when.

Regulatory compliance.

🔒 GDPR📜 LOPDGDD📋 DPA👁️ Access audit trail🔐 Encryption at rest & transit🧩 Field-level encryption of clinical data

Design commitments.

These principles aren't marketing. They're reflected in the product architecture and the DPA contract.

AI never issues diagnoses or treatment suggestions
Sensitive modules (location, wearables, AI, community) are only activated with the patient's express consent
Accesses are recorded in the audit log
Deletion rights are honoured under the GDPR, respecting legal clinical retention periods

Questions about the ethical or technical framework?

Clinical Safety & AI | Caminar Libre | Caminar Libre