Trust Center
This page is MedXline's public honesty board: which reviews are finished, which rules keep money out of doctor rankings, how AI is limited to help (not decide care), and how to ask for deeper security packs. A plan on a roadmap is never sold as a finished certificate.
Older trust and transparency links all land here — one place, one clear story.
How to read this page
Many trust pages blur finished reviews, plans, and built-in rules into one soft adjective. Here each status pill means exactly one thing.
An outside reviewer has issued a finished attestation or certificate, and we have it on file today.
An outside review has started. No finished certificate exists yet — and we do not pretend it does.
On the roadmap with an owner. Work has not started. This is an intention, not a finished control.
Our controls are built toward a published standard, with gaps written down. This is not a certificate.
A rule enforced in the live product (for example: ranking cannot be bought). Real — still not the same as an outside certificate.
Trust planes
Each plane is either enforced in the live product or published as a separate evidence state. None of them upgrades a Planned review into an Active certificate.
Doctor choice stays independent: Clinics cannot pay, bid, or use referral deals to climb search. The full blocked list lives only in the Doctor-choice section below — other pages should link there, not copy it.
Money and care events are hard to quietly rewrite: Important money and care-completion events are recorded in a way that makes silent edits detectable. Signed-in users can request deeper proof packs when needed.
Evidence before claims: Built-in rules, deployment setup, outside review, and legal authorization are kept as separate facts. Marketing language cannot upgrade a plan into a finished certificate.
Access is checked on the server: Who you are and what you may do is checked on the server — a visible button never replaces permission. Regions that are not authorized stay offline.
Doctor choice stays independent
MedXline blocks 13 money-and-marketing shortcuts from affecting who appears higher in search. Clinics cannot pay, bid, or use referral deals to climb the list. You can check any ranked result with the simple tools on this page.
Paying for a higher plan never moves a clinic up the list.
Buying a product package never buys a better rank.
Money spent on ads never changes search order.
Promotional boosts are never applied to rankings.
Referral deals between clinics never buy placement.
Sending more referrals never improves a clinician’s rank.
How much a clinic pays MedXline never affects order.
Software fees never purchase a higher listing.
There is no bidding for a better spot in results.
Credits and tokens never unlock higher placement.
A “featured” badge never overrides neutral ordering.
Commission rates never buy preferential ranking.
Partnership level never buys preferential ranking.
Live checks
These tools ask MedXline live questions. If something is down, this page says so — it never invents a perfect uptime score.
Open register change-checkTap Refresh to run a one-time availability check. Not an uptime promise.
Not on this public page
Clinic-count aggregates are not offered here. Use a clinic reference below, or open the platform overview.
A unique check code for the public standards and certifications list. Email alerts and automated monitors use this code — if it changes, the register changed.
Independent review
Every attestation MedXline holds, is pursuing, or has explicitly decided not to pursue — including empty rows. A register that only lists wins is a brochure.
Internal controls over financial reporting (ICFR) for the HIC ledger, payment intent state machine, mobile-money settlement reconciliation, and payout disbursement workflows.
Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy) covering the Next.js platform, Postgres tenant data plane, payment orchestration, and identity stack.
Information Security Management System covering all production cloud workloads, the engineering org, and supporting business processes (HR, vendor management, change management).
Privacy Information Management System extension to the 27001 ISMS, covering processing of patient PHI, member PII, and partner financial PII across all jurisdictions of operation.
Black-box + grey-box pentest of the Next.js public surface (auth, payments, partner portal, compliance console), authenticated APIs, and the cloud infrastructure perimeter (Vercel + Supabase + Upstash).
Card payment integration scope: tokenization via gateway, no PAN storage, partner-mediated card-on-file. Non-card mobile wallet settlement rails are out of PCI scope.
Deferred; not in the current public product scope. Tracked so governance reviews do not reintroduce it accidentally.
Standards alignment
10 of 17 standards are Aligned in the register; 4 Planned; 2 Monitoring only. Alignment means documented mapping with gaps recorded. It never upgrades a certification row to Active.
Reporting framework on controls relevant to Security, Availability, Confidentiality, Processing Integrity, and Privacy of a service organisation.
International standard for an Information Security Management System (ISMS) — risk-based controls covering organisation, people, processes, and technology.
Reporting framework on controls relevant to user entities' Internal Control over Financial Reporting (ICFR).
Privacy Information Management System (PIMS) extension to ISO/IEC 27001, providing requirements for processing personally identifiable information.
Application Security Verification Standard — a basis for testing web application technical security controls and providing a list of requirements for secure development.
Business Continuity Management System (BCMS) — requirements to plan, establish, implement, operate, monitor, review, maintain, and continually improve business continuity.
Payment Card Industry Data Security Standard — protects card-data environments through technical and operational requirements.
Fast Healthcare Interoperability Resources — modern web standard for exchanging healthcare information electronically.
Comprehensive, multilingual clinical healthcare terminology used for clinical documentation and reporting.
WHO International Classification of Diseases, 11th revision — global standard for diagnostic health information.
Health-sector application of ISO/IEC 27002 — security management in health using ISO/IEC 27002 controls.
Standards-based, Machine-readable, Adaptive, Requirements-based, Testable — WHO's framework for digital adaptation kits in health systems.
AI Management System — requirements for establishing, implementing, maintaining and continually improving an AI management system within an organisation.
AI Risk Management Framework — voluntary guidance to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.
Ethics and governance of artificial intelligence for health — six principles ensuring AI works to the public benefit of all countries.
Quality management systems for medical devices — requirements for regulatory purposes.
Regulatory framework for Software as a Medical Device — risk categorisation and clinical evaluation guidance.
Conformity matrix
Compact roll-up of strategic frameworks against contributing attestations. Not covered yet means no certification row claims that framework today — recorded honestly, not papered over.
Best register status: Planned. Contributors: SOC 2 Type II; Vulnerability Assessment & Penetration Test (baseline).
Best register status: Planned. Contributors: ISO/IEC 27001:2022 (ISMS); Vulnerability Assessment & Penetration Test (baseline).
Best register status: Planned. Contributors: ISO/IEC 27701:2019 (PIMS).
Best register status: Planned. Contributors: Vulnerability Assessment & Penetration Test (baseline); PCI DSS v4.0 Self-Assessment (SAQ A-EP).
No certification row currently claims this framework. Absence is recorded — not filled with marketing language.
No certification row currently claims this framework. Absence is recorded — not filled with marketing language.
Renewals and cadence
No ACTIVE attestations with expiry windows fall inside the next 365 days — because the register has no Active issued artefacts today. Planned and In-progress rows still carry renewal cadence as roadmap intent only.
Empty renewal queue is a consequence of zero Active certificates — not an all-clear. Roadmap cadences below are intentions with accountable owners.
Roadmap cadence: annual. Not an issued renewal window — status is Planned.
Roadmap cadence: annual. Not an issued renewal window — status is Planned.
Roadmap cadence: triennial. Not an issued renewal window — status is Planned.
Roadmap cadence: triennial. Not an issued renewal window — status is Planned.
Roadmap cadence: annual. Not an issued renewal window — status is Planned.
Roadmap cadence: annual. Not an issued renewal window — status is Planned.
Vulnerability assessment
Baseline outside security test (VAPT) is Planned until commissioned. Findings on record today: 0. An empty register is not a clean bill of health — it means no external engagement findings have been entered yet.
Fix target: 7 calendar days.
Fix target: 30 calendar days.
Fix target: 60 calendar days.
Fix target: 90 calendar days.
Fix target: Tracked — no fixed fix deadline.
Status flow: Open → Fixing → Fixed → Verified → or Open → Accepted risk (sign-off required).
AI governance
AI may organize and draft. It does not hold diagnostic or treatment authority. Framework mappings below are alignment claims from the standards register — not ISO 42001 certification.
Open full AI governance leafAssistive systems may draft, organize, or summarize. Qualified people keep diagnostic and treatment decisions; important actions need attributable review.
Well-known AI safety frameworks are design references in the standards register. Mapping is self-declared alignment, not an issued certificate.
Prompts, tools, and outputs are kept in bounds and checked per release — proven by evaluation runs, not by slogan.
AI features are designed to be opt-in with human review available. Each deployment must verify actual opt-out and audit behavior before promising it to users.
AI Management System — requirements for establishing, implementing, maintaining and continually improving an AI management system within an organisation.
AI Risk Management Framework — voluntary guidance to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.
Ethics and governance of artificial intelligence for health — six principles ensuring AI works to the public benefit of all countries.
Evaluation budgets and archived runs: /standards-and-compliance/ai-evaluations.
Identity assurance
Former public identity-verification feeds permanently redirect here. Older public identity feeds are turned off. What remains public is the assurance design: checks, decision bands, step-up, and human review.
Identity assurance combines document capture, a live presence check, and risk screening before elevated access unlocks.
Clear cases can move faster. Unclear or high-risk cases go to a human reviewer — automation never silently self-approves high risk.
Wallet, settlement, and privileged operations re-check session strength. A visible screen never replaces the server check.
Older public identity feeds are turned off. Posture is explained here; raw decision streams are not a public marketing product.
How records stay honest
Some older public data feeds are turned off until a safer replacement is ready. What stays available: clear rules for money and care events, and the ranking check on this page.
Money and care-completion events are added in order. Balances are calculated from those events — not casually overwritten totals.
Important decisions can carry a signed proof. Full enterprise proof packs stay behind a signed-in request; this public page explains the idea without dumping internals.
Anyone with the check code from a ranked result can confirm money-and-marketing shortcuts were not used — using the tools on this Trust Center (not a separate essay on every page).
Older public completion-rate and price feeds are turned off until a safer replacement is ready. The honesty rules remain; those live aggregate feeds are not advertised as available.
Evidence-based care tracking
Care-completion evidence is scored by source level plus logged modifiers. Self-report alone never clears high-stakes clinical steps.
Evidence sent automatically from integrated partner systems. Highest confidence when checks pass.
Staff confirm evidence through the partner portal with identity checks. Mid confidence.
Evidence a patient submits themselves. Lowest confidence, rate-limited, and never enough alone for high-stakes steps (labs, prescriptions, dispense).
Adjacent public surfaces
Many legacy trust URLs permanently redirect here. Security, privacy, disclosure, VAPT, and AI governance leaves remain bookmarkable detail pages.
Security contract
Least authority, human-owned clinical decisions, evidence before claims, and stay-off-until-authorized release — design posture without inventing certifications.
OpenCoordinated disclosure
Scope, out-of-scope, safe harbor, and how to report. Read before testing; stop if you encounter data that is not yours.
OpenResearchers
Acknowledgments for researchers who reported issues responsibly under the disclosure policy.
OpenPrivacy notice
How the public marketing site handles information. Separate from covered-entity clinical privacy claims.
OpenSecurity findings
Fix deadlines by severity, status workflow, and live finding counts from the same register summarized on this Trust Center.
OpenAI governance
Assistive-only boundaries, pre-release checks, prompt and tool defences, and human review points — detail page for the summary on this Trust Center.
OpenQuality bar
Published quality budgets per intent and archived run results — pass or fail from evaluation artefacts kept with the product.
OpenChange feed
Machine-readable posture changes for standards, certifications, and curated trust surfaces. Same change-check code as email alerts.
OpenProduct
How care journeys, partners, and compliance surfaces fit together as one operating system.
OpenReviewers
Route security questionnaires and NDA document requests to the MedXline team — not a generic sales forward.
OpenIntegrity
Jump to the change-check panel on this page — same code as email alerts and the machine-readable copy.
OpenAudit packs
Public surfaces answer early questions without inventing downloads. Detailed reports and questionnaire dumps require identity, purpose, and usually an NDA.
Contact for gated evidenceStatus, scope, and dates from the certifications register. Active requires dated proof on file.
Aligned / In progress / Planned / Monitoring from the standards register — alignment is not certification.
Fix deadlines and status flow publish even when findings count is zero. Baseline engagement remains Planned until commissioned.
Unique check code for the public standards and certifications list — same value email alerts and monitors compare against.
Coordinated vulnerability disclosure and public-site privacy remain dedicated pages.
Issued reports or in-progress engagement letters when they exist in the register. Released under NDA with documented business purpose.
External assessment summaries and remediation status. Detailed exploitable findings stay restricted.
Encryption, tenancy isolation, logging, incident response, and business continuity summaries for security reviewers.
Critical-vendor / subprocessor inventory and data-processing agreement templates for qualified enterprise reviewers under NDA. No public live subprocessor dump is published.
Mapped answers against this register — including lines where the honest answer is not yet done.
Email confirmation when the public compliance register changes. Same change-check code as the panel above.
Public marketing describes product architecture and trust posture only. Country authorization, residency, and market enablement are customer-specific and stay off until recorded through the gated review path — not inferred from a public inventory.
Request jurisdiction reviewFAQ
The same answers appear in search-friendly page markup. If a claim is not here, it is not a public trust claim.
Ask the register
When your device supports it, answers can run on-device. Otherwise the deterministic FAQ path answers from the same pairs above.
Bring the questionnaire
We answer against this register — attested, aligned, source-controlled, configurable, externally dependent, or not yet done. Including the lines where the answer is no.