Let's talk

Trust and compliance

PEGASI Trust Center

Current public documentation about our privacy, security and compliance program for SAIL, CONNECT and IOB.

Related to

Public documents

31 documents available

  • GDPRHIPAA

    Anonymization, Pseudonymization, and Data-Use Boundaries

    Summarizes identifiability-reduction techniques, reidentification controls, and boundaries for secondary uses and models. This summary covers corporate rules applicable to SAIL, CONNECT, IOB. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • HIPAAISO 27001ISO 27002

    Assets, Classification, and Information Handling

    Describes ownership, classification, handling, transfer, and disposal of assets and information. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • HIPAAISO 27001ISO 27002

    Backup, Restoration, and Recovery Testing

    Summarizes backup protection, retention, restoration, and periodic testing. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAAISO 27001

    Complaints, Authorities, and Customer Assurance

    Explains how complaints are received, authorities are supported, and customer statements or evidence are disclosed in a controlled manner. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAAISO 27001ISO 27002

    Continuity, Recovery, and Emergency Operations

    Describes impact analysis, priorities, continuity, recovery, emergency operations, and exercises. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAA

    Data Retention, Return, and Deletion

    Describes how retention periods, legal holds, return, deletion, and backup propagation are defined. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAA

    Data Safeguards, Access, and Approved Communications

    Summarizes boundaries for access, event logging, support, and communication of sensitive information. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAAISO 27001ISO 27002

    Document Control, Audit, and Continual Improvement

    Describes the approval, review, audit, correction, and management-review cycle applied to the program. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • CENS

    Electronic Health Record Software Quality Seal Certificate

    This entry presents an external validation issued by Chile's National Center for Health Information Systems (CENS) for an identified product and version. The certificate identifies PEGASI DE CHILE SPA as operator and PEGASI SAIL, version v1.97.128, as the evaluated software. It was issued in Santiago on December 18, 2025 and states validity through December 18, 2028.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAAISO 27001ISO 27002

    Encryption, Key, and Secret Management

    Summarizes requirements for encryption, certificates, keys, and secrets throughout their lifecycle. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAAISO 27001ISO 27002

    Event Logging, Monitoring, and Escalation

    Describes logging principles, protection of data in logs, monitoring, alerts, and escalation. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • HIPAA

    HIPAA Health-Information Safeguards and Risk Management

    Summarizes applicability, BAA agreements, minimum necessary, rights, risk analysis, contingency, and breaches under the HIPAA framework. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAAISO 27001ISO 27002

    Identity, Authentication, and Access Control

    Summarizes identity lifecycle, authentication, privileged access, service accounts, and periodic reviews. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • HIPAA

    Independent Health-Information Security Risk Assessment (2024)

    This entry summarizes an Information Systems Security Report prepared for Pegasi International, Inc. by HIPAA for Humans following an independent security risk assessment. Michael Herrick served as lead risk analyst, and the report is dated March 27, 2024. The assessment examined business processes and information technology infrastructure related to storing, transmitting, and protecting electronic Protected Health Information (ePHI).

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAAISO 27001ISO 27002

    Information Security Program

    Summarizes the objectives, principles, and responsibilities of the information-security program. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAAISO 27001

    Integrated Risk Management and Control Applicability

    Summarizes how PEGASI identifies, treats, accepts, and reviews risks and determines applicable controls. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • HIPAAHL7 FHIRISO 27001ISO 27002

    Integration and Interoperability Security

    Describes design, connectivity, access, and traceability controls applicable to integrations and interoperability interfaces. This summary covers corporate rules applicable to CONNECT, IOB. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • HIPAAISO 27001ISO 27002

    Network, Cloud, and Supply-Chain Security

    Describes principles for secure connectivity, segmentation, cloud services, and technology-supplier risks. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAA

    Personal-Data Breaches and Notification Support

    Summarizes detection, assessment, documentation, escalation, and controller support for a potential breach. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • HIPAAISO 27001ISO 27002

    Physical, Device, and Workforce Security

    Summarizes controls over facilities, equipment, media, remote work, and workforce changes. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPR

    Privacy by Design and Impact Assessments

    Explains how changes are assessed before real data is used and when a PIA or DPIA is required. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAAISO 27001

    Privacy Roles, Independence, and Oversight

    Explains the responsibilities of the DPO, Legal, Security, Product, and the functions that make or execute decisions. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPR

    Processing Inventory and ROPA Maintenance

    Explains how purposes, roles, categories, systems, recipients, regions, retention, and safeguards are recorded for each processing activity. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAAISO 27001

    Program Governance, Scope, and Responsibilities

    Presents the corporate scope, accountability lines, and interfaces of the security and privacy program. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAAISO 27001ISO 27002

    Secure Development, Configuration, and Change Management

    Describes how security requirements are incorporated into architecture, development, testing, configuration, changes, and releases. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAAISO 27001ISO 27002

    Security Incident Response and Learning

    Describes preparation, classification, response, evidence preservation, communication, and post-incident learning. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAA

    Sensitive and Health Data, Minimization, and Quality

    Describes enhanced safeguards, minimization, quality, and identifiability-reduction techniques. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAA

    Suppliers, Subprocessors, and International Transfers

    Explains due diligence, contracts, subprocessor changes, business associates, and territorial assessments. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAA

    Transparency, Notices, and Individual Rights

    Summarizes the notice lifecycle, consent where applicable, and verifiable handling of individual-rights requests. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAAISO 27001ISO 27002

    Vulnerability, Patch, and Security Testing Management

    Summarizes vulnerability identification, prioritization, remediation, verification, and coordinated disclosure. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document
  • GDPRHIPAAISO 27001ISO 27002

    Workforce Competence, Training, and Responsibilities

    Summarizes training, rule acknowledgement, confidentiality, and workforce-lifecycle requirements. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.

    Public version
    1.0.0
    Effective from
    Aug 1, 2026
    Next review
    Feb 1, 2027
    View document

Framework and control tags indicate a thematic relationship; they do not constitute a certification on their own.