AMANDIL · TRUST & SECURITY

Trust & Security

Amandil is built from public sources and does not take in your data. Agents you build can use your own data in your environment; it doesn't have to pass through us. That keeps the security picture short. This page says plainly what we hold, what we don't, and who to contact.

Last updated October 2, 2026

01

What Amandil is built from

Amandil is a model of how healthcare operates: its processes, regulations, standards and publicly reported performance. It is built from public sources, such as federal regulations, CMS data, industry standards and public announcements. It contains no personal data, and we do not ingest customers' private data to build or operate it.

02

No patient data

  • Amandil does not connect to your EHR, claims systems or data warehouse.
  • Our Platform Terms prohibit submitting protected health information (PHI) to the platform.
  • If a service ever would involve PHI, a Business Associate Agreement is signed first.
03

What we do hold

For a customer account, we hold account and contact details, and routine security and audit logs (records of authentication and API activity). For this website, we hold what you send through a contact form. Our Privacy Policy lists every collection point.

04

Access

  • Access to the service uses OAuth 2.0 or bearer tokens, which can be revoked immediately.
  • Each organization's access is scoped to its own grant.
05

Encryption

All traffic to this site and to our MCP service is encrypted in transit (HTTPS/TLS, with HSTS). The data we hold lives on our service providers' infrastructure, which encrypts stored data at rest.

06

Retention & deletion

On account closure or a verified request, we delete your account record within 30 days, except where law requires longer retention. Security and audit logs are not part of that deletion; we keep them for security, abuse prevention and legal compliance. See our Terms.

07

Sources on every answer

Answers from Amandil carry the source and, for performance data, the measurement period. Reference content is informational and should be verified against primary sources before decisions with clinical, legal or financial consequences.

08

Certifications

Amandil does not currently hold SOC 2 or HITRUST certification. We are a small team and will complete your security questionnaire directly. Email security@amandil.ai.

09

Reporting a security issue

Email security@amandil.ai with the subject line "[SECURITY]". We acknowledge reports within 5 business days, coordinate disclosure in good faith, and will not pursue legal action against researchers who report in good faith. Details are in our security.txt.

10

Related documents

Privacy Policy · Terms of Service · Platform Terms