Security Model

How we protect you by keeping medical data off our servers.

Browser Sandbox Isolation

Your DICOM files are processed entirely within the browser sandbox. The same-origin policy and Content Security Policy headers prevent unauthorised scripts from accessing your files or rendering data.

Cornerstone Rendering Library

Medical image rendering is powered by the open-source Cornerstone library — a widely-used, peer-reviewed framework for WebGL-based DICOM rendering. Pixel data is decoded and displayed locally without any intermediary server.

WebGL Local Rendering Pipeline

Window/level (WW/WC) adjustments, MPR reconstructions, and measurements are computed entirely on the GPU and CPU within your browser tab. No intermediate pixel data is exfiltrated during processing.

No Server-Side Pixel Storage

Our servers handle only authentication, project metadata, and analytics. Patient pixel data and DICOM tags are never written to our databases or file systems.

Responsible Disclosure

If you discover a security vulnerability, please report it via the contact details on the About page. We commit to acknowledging reports within 48 hours and addressing confirmed vulnerabilities promptly.