Security & Compliance

Data protection is product architecture, not an afterthought.

AESKONdocs is designed for special categories of personal data: minimise, separate, encrypt, delete — review and approve.

GDPR Art. 9 & 25

Health data and privacy by design are treated as product architecture, not a later add-on.

Hosting in Germany

The target architecture provides for processing and storage on German infrastructure (incl. IONOS Germany).

Pseudonymisation

Operational data and identifying assignment are kept separate; re-identification is controlled.

Encryption

Encryption on the device, in transit and at rest is a baseline — as are role permissions and auditability.

Deletion logic

Audio and transcript layers are meant to be temporary, not a permanent data store.

EU AI Act

AESKONdocs is set up as an assistance system with human approval — not an autonomous medical AI.

MDR / SaMD

Regulatory classification and SaMD questions are under review. No MDR certification is claimed.

Patent

Patent application filed with DPMA/EPO on 31 March 2026. The file number will be added before publication.

Guiding principle

AI assists. Humans decide.

A suggestion, not a command

Every AI output is a suggestion. Only active confirmation turns it into a record entry.

Traceable

For every suggestion it stays visible what it came from — reviewable and correctable.

Responsibility with the team

Medical responsibility and approval stay with the professionals, not the software.