Insights · 20 articles · 5 topics
How this softwareactually gets built.
Notes from the people building hospital platforms, clinical AI and the integrations between them. Written for the engineers, clinicians and security teams who have to live with the result.
No thought-leadership theatre. What we decided, why, and what we would do differently.
Reading
Latest articles.
Newest first. Filter by what you work on.
SecurityAudit trails that answer questionsMost audit logs are written to satisfy a requirement and discovered to be useless the first time somebody asks a real question of them. What changes when the log is designed around the questions instead.SecuritySaying 'encrypted' precisely'Encrypted' on its own is marketing. What it takes to make it a statement a security reviewer can check: the algorithms, the parameters, and the discipline of describing exactly what each one protects.SecurityWho can see what: identity and access before anything elseConsent, roles and context are settled early or patched forever. A look at how identity, RBAC and context-aware access are treated as part of the design in Zypocare One, not a layer added once the product works.SecurityThe risk you inherit from everything you connect toA platform's security posture includes every system it integrates with and every credential it holds on somebody's behalf. How we think about the blast radius of an integration, and why least privilege is an integration requirement.
Stay in the loop
Get new writing when it lands.
Occasional, technical, and never a newsletter for the sake of one. We will only write when we have something worth your time.