Enterprise
Run the same Records core inside your operating boundary.
Enterprise is the path for production data, controlled deployment, security review, custom retention, identity requirements, and governed support.
- Hosted or customer-managed
- No source payload retention
- Read-only by default
Start with the constraint
The right architecture follows from who operates Records and what data may cross the boundary.
Data
What may be processed?
Public, synthetic, or de-identified data by default. Production patient data requires a separately contracted, approved operating mode with explicit region, retention, security, and recovery controls.
Operator
Who must run it?
MedVertical, a contracted regional operator, or the customer inside a controlled environment.
Control
What must be proven?
Identity, audit, recovery, network, terminology, deployment, and evidence requirements for the review.
Operating controls
Enterprise controls support the Records core; they do not create a separate product.
Workspace access
Local authentication, optional TOTP MFA, workspace roles, scoped API keys, and platform-admin boundaries in the current product.
Security audit trail
Tenant-scoped security events and exports for access, configuration, and governed operations.
Controlled validation inputs
Pinned profiles, terminology sources, rules, thresholds, and environment context for reproducible runs.
Deployment runbooks
Defined startup, migration, backup, restore, release, and recovery gates for the selected operating contract.
Evidence deliverable
Give the reviewer the basis, not another dashboard claim.
A Records evidence record connects the selected run to its validator, package pins, terminology basis, thresholds, timestamps, findings, and integrity metadata.


A bounded evaluation
A useful evaluation begins with one decision and ends with explicit acceptance evidence.
- Step 1 of 4.
Select one workflow
Release, supplier comparison, reporting handover, research dataset, or agentic validation.
- Step 2 of 4.
Pin the basis
Server, dataset, profiles, terminology, rules, thresholds, and environment.
- Step 3 of 4.
Run the decision path
Validate, compare, investigate, re-run, and open the evidence record.
- Step 4 of 4.
Review the boundary
Agree what the evidence proves, what remains outside it, and whether deployment fit is established.
Continue with the review you actually own.
Deployment owns the operating model. Trust owns the data flow and assurance status. Enterprise owns qualification and evaluation fit.