Data Privacy & Compliance

Your Data Never Leaves

BonaLab deploys within your hospital's infrastructure. Images, annotations, and models stay behind your firewall, always.

Core Principle

BonaLab is designed for on-premise deployment. Your medical images, patient data, annotations, and trained models never leave your network.

On-Premise Architecture

Within Your Hospital Firewall

Your PACS/VNA

BonaLab connects directly to your existing imaging infrastructure. Images are pulled for annotation without ever leaving your network.

BonaLab Platform (On-Premise)

The platform runs on your infrastructure: your servers, your network, your control. Your clinical team annotates, trains models, and deploys AI without any external data transfer.

Your AI Models (Owned by You)

Models trained on your data belong to your institution. Deploy to your clinical workflows, integrate with your PACS, maintain full ownership.

No cloud dependencies. No external data transfers. No third-party access.

Regulatory Compliance

RegionRegulationHow BonaLab Complies
USA
HIPAAOn-premise deployment means PHI never leaves your network. No Business Associate Agreement required for the software itself. Your existing data governance applies.
EU
GDPRData stays within your jurisdiction. No cross-border transfers. Built-in deletion capabilities support right to erasure requirements.
UK
UK GDPR + NHSCompliant with Caldicott principles. Data minimization enforced, so only necessary metadata processed. Full audit logging for NHS data governance requirements.
South Africa
POPIAPurpose limitation enforced, so data is used only for the AI use cases you define. On-premise deployment ensures data remains under your organization's control.
FDA
AI/ML GuidanceModel documentation and validation workflows support regulatory submissions. Full training data provenance and versioning for FDA clearance requirements.

Security Controls

Access Control

Role-based access control (RBAC) with granular permissions. Integrate with your existing identity provider (LDAP, Active Directory, SAML).

Audit Logging

Comprehensive audit trails for all data access, annotations, model training, and deployments. Export logs to your SIEM for security monitoring.

Encryption

Data encrypted at rest and in transit. TLS 1.3 for all network communications. Support for your organization's encryption key management.

Network Isolation

Deploy in an air-gapped environment if required. No external network dependencies for core functionality. Optional telemetry can be disabled.

SOC 2 Controls

BonaLab implements controls aligned with SOC 2 Trust Service Criteria:

Security

Access controls, encryption, vulnerability management, incident response

Availability

High availability architecture, backup and recovery, disaster recovery

Processing Integrity

Data validation, quality assurance, error handling, audit trails

Confidentiality

Classification, encryption, access restrictions, secure deletion

Privacy

Consent management, data minimization, retention policies, access rights

Why On-Premise Matters

No Data Sharing Agreements Needed

Because data never leaves your network, you don't need to negotiate complex data sharing agreements or wait months for legal review. Deploy and start labeling immediately.

Your Models, Your IP

AI models trained on your data belong to your institution. No vendor lock-in, no shared model weights, no questions about intellectual property.

Simplified IRB Approval

For research use cases, keeping data on-premise simplifies IRB review. No external data transfers to justify, no third-party access to document.

Full Audit Control

All logs, access records, and audit trails remain under your control. Integrate with your existing security monitoring and compliance infrastructure.

Frequently Asked Questions

Does BonaLab ever access our data?

No. BonaLab is software that runs on your infrastructure. We provide the platform; you operate it. We have no access to your data, images, annotations, or models unless you explicitly grant access for support purposes.

What about software updates?

Updates are delivered as versioned releases that your IT team applies on your schedule. For air-gapped environments, updates can be delivered via secure media. No automatic updates that might affect your production systems.

Can we run BonaLab in a cloud environment?

Yes. BonaLab can run on cloud infrastructure (AWS, Azure, GCP) within your organization's VPC. The key is that you control the environment. It's your cloud account, your network, your data. We also offer a managed cloud option for organizations that prefer it.

How does BonaLab handle de-identification?

BonaLab integrates with your existing de-identification workflows. We recommend de-identifying images before annotation if you're using the platform for research or if annotators shouldn't see patient identifiers. The platform supports both identified and de-identified workflows based on your requirements.

What support is available for compliance?

We provide documentation, deployment guides, and security questionnaire responses. Our team can participate in security reviews and assist with compliance documentation. For enterprise customers, we offer dedicated compliance support.

Questions?

Our team is happy to discuss compliance and security requirements for your deployment.

Contact Compliance Team