Compliance & Security

    HIPAA compliant
    AI radiology reporting

    Every xAID CT report is HIPAA compliant, processed on US-based infrastructure, and reviewed by our in-house radiologist. BAA available before your pilot begins — no commitment required

    Request BAA & start pilot

    Security & compliance at every level

    HIPAA

    HIPAA compliant

    All PHI handled in compliance with HIPAA. US-based AWS infrastructure, encrypted in transit and at rest. No data leaves US servers

    ISO 27001

    ISO 27001 certified

    xAID is ISO 27001 certified — an internationally recognized information security standard, verified by annual third-party audit

    BAA Ready

    BAA available

    Business Associate Agreement available before you begin — including the free pilot. No commitment required to sign a BAA

    US-Based

    US-based infrastructure

    All data processed and stored on AWS infrastructure in the United States. Zero-footprint viewers — no images or reports cached outside US servers

    Radiologist Reviewed

    Radiologist review on every report

    Every xAID report is reviewed by our licensed, credentialed in-house European radiologist. AI-assisted, not autonomous — your radiologist delivers the final report

    Audit Ready

    Access controls & audit logs

    Role-based access control, full audit logging, and session management across all data interactions. Supports your HIPAA compliance program

    Radiologist review on every report

    xAID is AI-assisted, not autonomous. The final report is always reviewed by our in-house European radiologist — making the accountability model identical to traditional teleradiology

    01

    AI analyzes the study

    Two AI layers process 100+ findings across head, chest, or abdomen CT

    02

    Radiologist reviews

    Licensed, credentialed European radiologist reviews the AI draft and all findings

    03

    Radiologist signs off

    The radiologist is professionally accountable for the report content and approves it before delivery

    BAA before your first study

    We provide a Business Associate Agreement before you send a single study — including the free 5-study pilot. No integration required, no commitment. Your compliance requirements are covered from day one

    Request BAA & free pilot

    Compliance questions

    Yes. All PHI is processed on US-based AWS infrastructure, encrypted in transit and at rest. Zero-footprint viewers — no data leaves US servers. BAA available before you begin

    Yes — as with any vendor that handles PHI, a BAA is required under HIPAA. xAID provides the BAA before your pilot begins. It covers the full scope of data handling and takes minutes to execute

    The European radiologist who reviews the report is professionally accountable for its content. xAID is AI-assisted, not autonomous. No report is delivered without radiologist review

    No. All data is processed and stored on AWS infrastructure in the United States. Zero-footprint viewers — CT images and reports are never cached on devices or transferred outside US servers

    Yes. xAID is ISO 27001 certified, verified by annual third-party audit. ISO 27001 is the internationally recognized standard for information security management systems