Every claim below is verifiable. We inherit the certifications of our infrastructure partners — Groq (inference), Google Cloud (hosting, auth, database), Razorpay (payments), and Resend (email). We publish what we have, what we don't have, and what's still in progress. Honesty is a security feature.
All traffic encrypted in transit with the latest TLS standard.
Firestore + Cloud Storage encrypted with AES-256 by default.
Customer-Managed Encryption Keys available for Enterprise.
Identity via Google. Zero passwords stored on our servers.
Auto-rotated session tokens issued by Firebase Auth.
Firestore blocks all reads/writes unless explicitly permitted.
Role-based access control — users read only their own data.
Every service, function, and user gets minimum required access.
Uploaded files held in memory only for inference duration.
Your uploads never train or fine-tune any model, ever.
Full account and history deletion within 30 days of request.
Firestore data replicated across regions for durability.
Qwen 3.8 27B served on Groq's LPU inference stack.
Groq maintains independent SOC 2 Type II attestation.
Inference runs in US data centers with redundant failover.
Groq does not store inference inputs/outputs on their side.
Highest level of payment card security certification.
Razorpay holds current information security certification.
Independently audited security, availability, confidentiality.
Reserve Bank of India Payment Aggregator license.
Google Cloud holds all three SOC audit reports.
Cloud-specific, PII, and privacy management certifications.
BAA available via Google Cloud for PHI workloads.
Published service level from Firebase + Cloud Functions.
AI management system domains aligned (2023).
AI Risk Management Framework mapped end-to-end.
AI literacy obligations aligned for providers and deployers.
Aligned with WHO guidance on AI ethics for health.
Medical device risk management framework aligned.
Medical device software lifecycle processes aligned.
HL7 FHIR readiness for EHR integrations.
Outputs require independent verification before any clinical use.
Not a cleared medical device in the United States.
Not a marked medical device in the European Union.
Educational and research use only. Not for clinical practice.
Every scan produces a formal clinical imaging report. Structured like a radiologist's report, cross-referenced with live literature, and exportable to a multi-page PDF with your patient's details and your scan image on the letterhead.
Auto-detected from the image — e.g. "CHEST X-RAY · PA View", "CT BRAIN · Axial", "MRI KNEE · Sagittal".
6–12 discrete clinical sentences covering anatomy, margins, densities, and any abnormalities — each a complete observation.
One-sentence diagnostic conclusion. "No abnormality detected" when the scan is normal, or the leading diagnosis otherwise.
One-line recommendation — often "clinical correlation recommended" or a specific next step.
3–6 conditions ranked most-to-least likely, each with a rationale. Cross-referenced against live literature where applicable.
3–6 specific next steps — additional imaging, labs, referrals, or conservative management recommendations.
Up to 14 recent publications from PubMed, arXiv, and ClinicalTrials.gov, with clickable links to the source papers.
Multi-page PDF with letterhead, patient details, your scan image, all sections, and a full bibliography.
Every report is stored under your account with patient name, case ID, and timestamp — retrievable anytime.
Sign in with Google. Attach a scan. Enter the patient's name, age, and gender. That's it — the pipeline does the rest in 15–30 seconds.
One-click Google OAuth. No passwords, no email verification, no credit card. Account is live the moment you consent.
Drop a chest X-ray, CT, MRI, or histopathology slide. Full image is used — no cropping. Multi-image uploads for longitudinal comparison.
Name, age, and gender. Required for the report letterhead. Stored alongside the report in your private history.
Five sequential steps: vision extraction → literature search → impression → differential + management → final assembly. Qwen 3.8 27B on Groq processes each step in under 5 seconds.
The report appears in chat. Click EXPORT PDF to download a clinical-grade document with your patient details, the scan image, all sections, and citations.
One model. Every modality. Every scan produces the same structured report format.
Lung fields, cardiac silhouette, mediastinal contours, pleural spaces, osseous structures. Detects consolidation, effusion, pneumothorax, cardiomegaly, and more.
Chest, abdomen, brain, pelvis. Identifies masses, nodules, infiltrates, hemorrhage, fractures, and vascular pathology with anatomical localization.
Brain, spine, joints. Evaluates signal abnormalities, mass effect, midline shift, ligamentous injury, and soft tissue pathology.
X-rays of elbows, knees, hips, wrists, ankles, spine. Fracture detection, joint space narrowing, osteolysis, implant loosening, and degenerative changes.
Whole-slide images and tissue patches. Malignant features, mitotic activity, architectural atypia, and tissue characterization.
Lesion morphology, borders, pigmentation, ABCDE criteria. Detects features concerning for malignancy or infection.
Qwen 3.8 27B is a 27-billion-parameter multimodal model from Alibaba's Qwen series, serving both image and text inputs with native JSON mode and strong instruction following.
| Attribute | Specification |
|---|---|
| Architecture | Hybrid Gated DeltaNet + Gated Attention |
| Input modalities | Text, images (max 3 per request, 2048 tokens/image) |
| Output modality | Text only (JSON-native) |
| Context length | 131K tokens |
| Reasoning modes | Thinking + Instruct (switchable per request) |
| Tool use | Function calling + tool orchestration |
| Multilingual | Strong multilingual support (EN, ZH, and more) |
| GPQA Diamond | 89.2% |
| LiveCodeBench v6 | 90.3% |
| IFBench (instruction following) | 79.5% |