A glass box, not a black box.
Every interpretation Vitrubo produces can be inspected: what was stated, and the clinical source it rests on. This page sets out how that works, and how we handle security and privacy.
Glass box transparency.
Built to glass box requirements. Every statement carries the guidance it rests on, so the clinician can independently review the basis for it rather than rely on the software. In the United States that architecture is what allows software to inform clinical judgment without being regulated as a medical device.
US counsel review of the current version is under way. Legal opinions are scope-specific and version-specific.
Cited, claim by claim.
Each statement links the clinical guideline it rests on, for example EHA, WHO, NICE, KDIGO, BSH, FDA. Up to 30 sources can stand behind a single biomarker view.
One click to the publication.
Source chips open the actual guideline, the same page a clinician would read.
Boundaries built in on purpose.
Vitrubo's assistant is designed to the FDA's standard for a non-medical device, so the boundaries are part of the product:
- Never diagnoses or claims the user has a specific condition.
- No probabilities, no disease risk scores.
- Never prescribes medication or supplements, never advises changing them.
- Says "associated with", not "caused by"; causality is never asserted.
- On an alarming value, calmly suggests seeing a doctor.
- Answers only about health and labs.
- Writes only confirmed facts to the record, and asks first when wording is ambiguous.
Architecture choices that protect people.
Grounded in medical guidance.
Connections and explanations are built from named guidances, not from model memory.
Verification runs in deterministic code.
Parsing, units, reference ranges and abnormality flags are computed by code. No number is ever written by the model.
Models check each other.
Several AI models review the same case. Disagreements resolved, omissions caught, completeness enforced.
Identity never enters the prompt.
Personal identity is architecturally separated from clinical data; models see values, never personal data (PII / PHI).
Your data, in your region, under your terms.
Your record is never sold or shared. Sharing is opt-in, per profile, and revocable. Residency in EU, UK and US; identity separation is architectural, not procedural; retention configurable per deployment.
Security & privacy in fullCertifications.
Encryption in transit and at rest
In perimeter deployments key management stays with you. Controls and scope are described in the Trust Center.
HIPAA · GDPR
HIPAA business associate agreement for US deployments. GDPR Article 28 processing agreement and Standard Contractual Clauses as standard.
Need the details?
We share our security documentation with prospective partners.