Walk Into an Inspection With the Answer Already in Hand | Salus Agentic
Product

Walk Into an Inspection With the Answer Already in Hand

Role-based access, full audit trails, and a cryptographically verifiable chain of custody back up every result, so no question about who did what, and when, goes unanswered.

Salus handles protected health information, so security is foundational, not an add-on. Access is least-privilege, every action is audited, sensitive fields are encrypted, and every result carries a chain of custody you can verify.

The controls align with the frameworks public health programs rely on, HIPAA, NIST, CLIA, CAP, and ISO 15189, and because all protected health information lives in Snowflake under a Business Associate Agreement, Salus inherits Snowflake's certifications, including FedRAMP, StateRAMP, SOC 1 and SOC 2 Type II, HITRUST CSF, and ISO 27001.

Salus, chain of custody

What it does.

The full capability set, not a highlight reel.

Lab-scoped RBAC

Roles and permissions are scoped per lab, so access matches each person's actual responsibilities, enforced on every mutating action.

Real authentication and MFA

Password login with scrypt hashing and signed JWTs, with TOTP multi-factor authentication and SSO/SCIM provisioning available.

Comprehensive audit trails

Every significant action is recorded, who did what, and when, for inspection and incident review.

Field-level encryption

Sensitive identifiers such as patient names and MRN are encrypted, with blind-index search so they stay usable.

Verifiable chain of custody

Specimen events and released results are written to an append-only, cryptographically anchored ledger, so custody is tamper-evident end to end.

Automatic logoff

Idle sessions log off automatically, a HIPAA technical safeguard, without staff having to think about it.

In practice.

What it looks like on a real lab day.

An accreditation inspection

An inspector asks who verified a result three months ago. The audit trail and custody record answer in seconds.

Tamper-evident results

Because custody is cryptographically anchored, a result's history can be verified without trusting any single database administrator.

Who is in control.

  • AI personas hold scoped permissions that mirror staff roles, and only a human can fully disable a persona.
  • Every persona control action is written to an append-only log, alongside the rest of the audit trail.

Configuration.

What your lab controls, without a vendor in the loop.

  • Define roles and permissions, scoped per lab, on the admin Permissions screen
  • Require TOTP multi-factor authentication; configure SSO and SCIM
  • Enable field-level encryption for sensitive identifiers

See it in your laboratory's context.

Explore the live demo, no login and no request form.