Data Privacy & Compliance
Your Data Never Leaves
BonaLab deploys within your hospital's infrastructure. Images, annotations, and models stay behind your firewall, always.
Core Principle
BonaLab is designed for on-premise deployment. Your medical images, patient data, annotations, and trained models never leave your network.
On-Premise Architecture
Within Your Hospital Firewall
Your PACS/VNA
BonaLab connects directly to your existing imaging infrastructure. Images are pulled for annotation without ever leaving your network.
BonaLab Platform (On-Premise)
The platform runs on your infrastructure: your servers, your network, your control. Your clinical team annotates, trains models, and deploys AI without any external data transfer.
Your AI Models (Owned by You)
Models trained on your data belong to your institution. Deploy to your clinical workflows, integrate with your PACS, maintain full ownership.
No cloud dependencies. No external data transfers. No third-party access.
Regulatory Compliance
| Region | Regulation | How BonaLab Complies |
|---|---|---|
USA | HIPAA | On-premise deployment means PHI never leaves your network. No Business Associate Agreement required for the software itself. Your existing data governance applies. |
EU | GDPR | Data stays within your jurisdiction. No cross-border transfers. Built-in deletion capabilities support right to erasure requirements. |
UK | UK GDPR + NHS | Compliant with Caldicott principles. Data minimization enforced, so only necessary metadata processed. Full audit logging for NHS data governance requirements. |
South Africa | POPIA | Purpose limitation enforced, so data is used only for the AI use cases you define. On-premise deployment ensures data remains under your organization's control. |
FDA | AI/ML Guidance | Model documentation and validation workflows support regulatory submissions. Full training data provenance and versioning for FDA clearance requirements. |
Security Controls
Access Control
Role-based access control (RBAC) with granular permissions. Integrate with your existing identity provider (LDAP, Active Directory, SAML).
Audit Logging
Comprehensive audit trails for all data access, annotations, model training, and deployments. Export logs to your SIEM for security monitoring.
Encryption
Data encrypted at rest and in transit. TLS 1.3 for all network communications. Support for your organization's encryption key management.
Network Isolation
Deploy in an air-gapped environment if required. No external network dependencies for core functionality. Optional telemetry can be disabled.
SOC 2 Controls
BonaLab implements controls aligned with SOC 2 Trust Service Criteria:
Security
Access controls, encryption, vulnerability management, incident response
Availability
High availability architecture, backup and recovery, disaster recovery
Processing Integrity
Data validation, quality assurance, error handling, audit trails
Confidentiality
Classification, encryption, access restrictions, secure deletion
Privacy
Consent management, data minimization, retention policies, access rights
Why On-Premise Matters
No Data Sharing Agreements Needed
Because data never leaves your network, you don't need to negotiate complex data sharing agreements or wait months for legal review. Deploy and start labeling immediately.
Your Models, Your IP
AI models trained on your data belong to your institution. No vendor lock-in, no shared model weights, no questions about intellectual property.
Simplified IRB Approval
For research use cases, keeping data on-premise simplifies IRB review. No external data transfers to justify, no third-party access to document.
Full Audit Control
All logs, access records, and audit trails remain under your control. Integrate with your existing security monitoring and compliance infrastructure.
Frequently Asked Questions
Does BonaLab ever access our data?
No. BonaLab is software that runs on your infrastructure. We provide the platform; you operate it. We have no access to your data, images, annotations, or models unless you explicitly grant access for support purposes.
What about software updates?
Updates are delivered as versioned releases that your IT team applies on your schedule. For air-gapped environments, updates can be delivered via secure media. No automatic updates that might affect your production systems.
Can we run BonaLab in a cloud environment?
Yes. BonaLab can run on cloud infrastructure (AWS, Azure, GCP) within your organization's VPC. The key is that you control the environment. It's your cloud account, your network, your data. We also offer a managed cloud option for organizations that prefer it.
How does BonaLab handle de-identification?
BonaLab integrates with your existing de-identification workflows. We recommend de-identifying images before annotation if you're using the platform for research or if annotators shouldn't see patient identifiers. The platform supports both identified and de-identified workflows based on your requirements.
What support is available for compliance?
We provide documentation, deployment guides, and security questionnaire responses. Our team can participate in security reviews and assist with compliance documentation. For enterprise customers, we offer dedicated compliance support.
Questions?
Our team is happy to discuss compliance and security requirements for your deployment.
Contact Compliance Team