Trust, stated plainly.
OneDose agents handle protected health information and talk to patients about their medication, which makes trust a design question rather than a marketing one. This page states the principles that govern that: where the line between an agent and a clinician sits, what gets logged, what we can evidence today, and what we deliberately will not claim.
The two pages this one routes to go deeper: /security on the controls, /compliance on which rules apply where.
What principles govern this?
Agents collect and escalate. Clinicians decide.
Clinical questions, low-confidence cases and any sign of deterioration route to a human with the full context attached. No agent diagnoses, triages a symptom to a conclusion, or tells a patient whether to continue a medication. This is a design constraint rather than a setting — it is a patient-safety boundary first, and the thing that keeps the product on the right side of medical-device rules second.
The agent says it is an agent.
Every call opens with the agent identifying itself as an AI agent. Passing an agent off as a human is a trust problem and, in a growing number of jurisdictions, a legal one. A patient who asks for a person gets one, immediately, without a retention attempt.
Every action is logged.
Who did what, when, and why — across the whole journey rather than per tool. If anything is ever investigated, that log is the evidence, and a system that cannot produce one cannot demonstrate it behaved even when it did.
We do not publish a number we cannot attribute.
You will notice an absence of outcome percentages across this site. Figures like "reduces readmissions by X%" are only meaningful with the deployment, the cohort and the measurement attached, and OneDose does not currently have a figure it can attribute that way. When it does, it will appear with its source. Until then the pages argue from mechanism, which is more specific than a number anyway.
We do not name an integration we have not confirmed.
Integration depth varies by system and region. Rather than publish a matrix asserting depth nobody has verified per system, we will confirm what is live for your estate in writing before you commit to anything. A partner who scopes a build against an aspirational list has a much worse problem than one who asked.
A badge is not evidence — including ours.
If you are evaluating OneDose for anything that matters, ask for the report and its scope rather than reading a page. A SOC 2 covering a different system than the one you are buying is a common and entirely legal way to display a logo that means nothing to you. Apply that standard to every vendor in your comparison, us included.
What can we evidence today?
Generated from our configuration rather than maintained by hand, so it cannot drift ahead of what we can actually produce. Where an item says Evidence on request, ask and we will provide it — that is not a deflection, it is the state of what is attached to this page today.
- Evidence on request
HIPAA compliant
BAA on every deployment
- Evidence on request
SOC 2 Type II
End-to-end encryption
- Evidence on request
ABDM-ready · ISO 27001
Audit log on every action
- Evidence on request
Regional data residency
IN · US · EU
- Evidence on request
Business Associate Agreements (BAA)
Signed as standard
- Evidence on request
End-to-end encryption
In transit and at rest
- Evidence on request
Full audit logs
On every agent action
Where should you go next?
The controls, the regime, and the specific questions worth putting to us — and to every vendor you are comparing us against.