Product boundary
V1 is positioned as reporting assistance: dictation, formatting, proofreading, rewrite suggestions, templates, explicit approval for review edits, and audited safe cleanup.
Every claim on this page maps to a control in code, a contract artifact in motion, or a regulatory position we deliberately do not assert. Maintained continuously, not at launch.
Reporting assistance
Human-approved
Not server-archived
EU-first
Live safeguards in production, contract terms customers should expect, and claims that wait until the underlying evidence is in place.
V1 is positioned as reporting assistance: dictation, formatting, proofreading, rewrite suggestions, templates, explicit approval for review edits, and audited safe cleanup.
Review-class AI edits are review-gated, hash-bound, and visible before they change report text. Safe cleanup is auto-applied only after audit controls pass. Stale edits cannot apply.
Workspace report text is not maintained as a server-side archive. Account export exists and excludes report text by design.
Live dictation uses temporary, server-issued credentials and the configured realtime dictation route. Depending on provider and deployment, audio can stream directly to the provider or through backend proxy endpoints.
Revelar is not positioned as autonomous diagnosis, finding detection, triage, treatment advice, follow-up, or image interpretation.
Revelar does not acquire, process, or analyse medical images. Image-based inference is outside the V1 product scope.
Identifiable patient data belongs behind customer terms, signed DPA, privacy review, and verified subprocessor evidence.
Active processing is EU-first. Broader residency claims wait for vendor evidence on support, logs, backups, and subprocessor regions.
A staged plan toward formal procurement readiness. We publish what is complete, what is in motion, and what is deliberately deferred.
Lock the intended-use boundary in code, prompts, and tool profiles before evidence work begins.
Public privacy, legal, and trust pages aligned to current architecture and non-claim policy.
Collect signed DPAs, regional terms, and retention details from every active subprocessor.
Counsel-reviewed customer DPA, DPIA support template, and pilot-readiness checklist.
Procurement-grade security overview backed by encryption, access, SDLC, and incident evidence.
Evaluate ISO 27001 readiness and re-test the MDR boundary against pilot product behaviour.
These are product controls running in code today. They form the working base for privacy, security, and clinical procurement evidence.
Workspace report text is not maintained as a server archive. Account export excludes report text by design.
Review-class AI edits stay pending until the radiologist approves them. Safe cleanup is audited when it auto-applies.
Edit tools require a fresh report hash. Stale edits are rejected before they reach the editor.
Proofread, format, and rewrite lanes have separate tool profiles. The default assistant cannot call clinical reasoning tools.
Draft report text lives in the user's browser. The server keeps no persistent report archive.
Supabase RLS, auth checks, and organization membership checks protect account and organization data.
The service worker does not cache reports or API responses, so report content stays off offline caches.
Live dictation uses short-lived server-issued credentials or routes for the configured provider. Audio handling is provider- and deployment-dependent, including direct browser streams or backend proxying.
Every artifact below maps to a live product control, a vendor contract, or a counsel decision. Status reflects the current state of the file in the repository.
Vendors that may process data when their feature is in use. Full DPAs, regional evidence, and retention terms are tracked inside the vendor evidence program.
A clear boundary for users, customers, and procurement. Stronger claims arrive only after the underlying evidence does.
V1 is intentionally narrow reporting assistance. We do not claim medical device status until classification, QMS, and clinical evaluation work is in place.
AI literacy and transparency obligations are tracked, but a compliance claim waits for classification, risk management, and conformity work.
These are procurement evidence regimes, not legal requirements. Audited certification follows the security pack, not the other way around.
Active processing is EU-first. A full residency claim requires vendor evidence on support access, logs, backups, and subprocessor regions.
ZDR may hold for a specific AI route once contract evidence confirms it. It cannot be claimed across logs, auth, billing, support, or telemetry by default.
Diagnosis, triage, severity, staging, follow-up, and missed-finding reduction are out of scope for V1 and require a deliberate medical-device track.
Mandatory and expected company pages, one click away.
How account data, workspace text, AI processing, dictation, processors, retention, rights, and cookies are handled.
Legal noticeCompany identity, registered address, enterprise and VAT number, contact, terms boundary, and product non-claims.
Privacy mailboxUse privacy@revelar.xyz for rights, deletion, DPA, and processor questions. Use support@revelar.xyz for product support.