One rule sits above the others: we never claim what we cannot substantiate.
We sell into public health, emergency management, and education. In those rooms an overstated claim is not marketing enthusiasm — it is the reason a procurement officer stops the conversation. This page is written to be checked.
§ 01
What we do not do
No invented customer counts, deployments, compliance status, certifications, uptime, traction, revenue, or institutional relationships. A demo screen showing sample data says so on the screen. An empty state is shown empty.
Coverage is not customers
Global Health IQ monitors 190 countries. That is the reach of the data, and we describe it that way. It has never meant 190 countries of users, and we do not let it read as though it does.
Simulation is labelled
Every PRODIGY surface on this site is exercise data, and says so in the frame and in the caption. Generated scenarios do not represent any live agency deployment.
Availability, not control
SerpenOps reports observed pass windows and link budget for third-party spacecraft. It does not offer, and we do not claim, the ability to command another operator's assets.
§ 02
Maturity labels
Every system on this site carries one of these, everywhere it appears. They mean what they say.
§ 03
Security
We are hardening the technical and security architecture toward SOC 2 alignment. We hold no SOC 2 report today, and we do not display a badge implying one. When an audit window completes and a report exists that we can hand a reviewer, this page will say so and name the date.
Uptime and latency
Where we state service targets, they are targets. We do not present an aspiration as a contractual SLA before one is signed.
Regulated workloads
Clinical logistics raise HIPAA and BAA questions on the first call. Ask us directly and you will get our current posture, not a deflection.
§ 04
Data handling
Vault exists so institutional data does not have to move to become useful. Bring your own storage; applications reach it through a bridge and never hold your provider's tokens.
We use the word "encrypted" only where content is genuinely unreadable without a key. Access control and masking are described as access control and masking, because they are different guarantees.
Once authentication and persistence are real, COPPA and FERPA are live obligations rather than roadmap items. We treat them that way from the first signup.
§ 05
Privacy & civil liberties
Systems that score people by employer pedigree carry adverse-impact exposure the moment they touch hiring, contracting, or vendor selection. We removed that framing from our document intelligence rather than ship it and manage the consequences later.
The same reasoning applies to relaying live authentication codes between people: it defeats the second factor and breaks the terms of the services it touches. The legitimate version is per-person identity, so that is what we build.
Where our systems support emergency and public-health decisions, a human remains accountable for the decision. Governed Autonomy is a design constraint, not a feature we can be talked out of.
Sub-processors
The current list of infrastructure, model, and service providers used to deliver each system — including which system uses which — goes to any prospective institutional partner who asks.
Request the list →Reporting
Security issues, inaccurate claims on this site, or a system behaving in a way that contradicts what we have written here — all go to the same address, and all get a reply.
info@serpensinc.com →