ScanFlo

Security & trust

The easiest security review your IT team will do this year.

ScanFlo is a training simulator, not a clinical system. That one fact removes most of the risk surface before the checklist starts.

No patient data. Ever.

ScanFlo is a simulation environment. Every image is synthetically generated from virtual cases — no clinical images, no PHI, no DICOM from your systems. There is nothing patient-identifiable to protect, because none enters the platform.

No clinical integration

ScanFlo does not connect to PACS, RIS, EHR or any clinical network. It runs in a browser against our cloud — deployment requires no IT integration project and no clinical-network review.

Minimal personal data

We store what an education account needs: name, email, institution (if applicable), plan and licensing state, and learning progress. No health data, no biometric data, no payment card numbers on our servers (payments are processed by our payment providers).

Controls

What we run in practice

  • Encryption in transit (TLS) across all endpoints
  • Per-device licensing with server-side session revocation
  • Role-based access: learner, instructor and admin scopes
  • Institutional data separated per organization account
  • Payment card data handled by PCI-DSS-compliant processors — never stored by ScanFlo
  • Infrastructure hosted on AWS with automated certificate management

Institutional customers can request our current security summary and data-processing terms as part of procurement — contact@scanflo.io. See also our privacy policy and terms of service.

Questions your IT team wants answered?

Bring them to a demo — short answers, no theater.