Privacy & Security

Privacy-first data handling and enterprise-grade security

Designed for clinical environments. AR is designed to support clinical workflows while respecting patient privacy and data governance requirements.

Privacy and Security in clinical environment

Security foundations & privacy

AR is designed with healthcare security principles from the start.

01

Privacy & data handling

AR processes only the data required to support diagnostic workflows, such as:

  • Appointment identifiers
  • Diagnostic measurements
  • Reports and structured outputs

We do not collect consumer analytics or sell data. Data is used solely to match studies to appointments, generate diagnostic reports, return results to the EMR, and maintain auditability.

Data ownership: Clinics retain ownership of their data. AR acts as a processor, not a data owner.

Privacy and data handling
02

Security foundations

AR is designed with healthcare security principles from the start:

  • Encryption in transit and at rest
  • Role-based access controls
  • Auditability of access and actions
  • Least-privilege design throughout the system

Security is enforced at the platform level — not left to individual users.

Healthcare security
03

Cloud architecture & hosting

AR is cloud-native and hosted on AWS.

  • No local servers required
  • Centralized updates and patching
  • Scalable infrastructure for high-volume clinics and long-term archiving
  • Secure browser-based access

Reduces on-site IT burden while maintaining enterprise-grade controls.

Cloud hosting
04

Access control & auditability

  • User access is role-based and scoped
  • All significant actions are logged
  • No silent overwrites
  • Complete audit trails support clinical, legal, and compliance review

Administrative controls allow clinics to manage users, access, and permissions.

Every change is attributable. Nothing disappears.

Access control and audit
05

Integration philosophy

We integrate — we don't isolate.

  • Works alongside existing PACS and EMR systems
  • Standards-based interfaces where appropriate
  • Incremental adoption with no rip-and-replace

Your existing systems remain the systems of record.

Integration with clinical systems

Canadian privacy compliance

Canadian privacy compliance

AR is designed to support compliance with Canadian privacy requirements, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial health privacy legislation.

Patient data is:

  • Processed solely to support clinical diagnostic workflows
  • Access-controlled and auditable
  • Not sold, shared, or used for secondary purposes

Data handling practices align with Canadian healthcare privacy expectations. AR infrastructure can be deployed in Canadian cloud regions where required.


Your rights and controls

Access to data is role-based and auditable.

Role-based access

Access is scoped by role — users see only what they need.

Administrative controls

Clinics can manage users, access levels, and permissions directly.

Data ownership

Clinics own their data. AR acts as a processor, not a data owner.


Questions from IT or procurement?

Review AR's privacy and security architecture with our team.