Trust and compliance
PEGASI Trust Center
Current public documentation about our privacy, security and compliance program for SAIL, CONNECT and IOB.
Related to
Public documents
31 documents available
- View document
Anonymization, Pseudonymization, and Data-Use Boundaries
Summarizes identifiability-reduction techniques, reidentification controls, and boundaries for secondary uses and models. This summary covers corporate rules applicable to SAIL, CONNECT, IOB. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Assets, Classification, and Information Handling
Describes ownership, classification, handling, transfer, and disposal of assets and information. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Backup, Restoration, and Recovery Testing
Summarizes backup protection, retention, restoration, and periodic testing. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Complaints, Authorities, and Customer Assurance
Explains how complaints are received, authorities are supported, and customer statements or evidence are disclosed in a controlled manner. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Continuity, Recovery, and Emergency Operations
Describes impact analysis, priorities, continuity, recovery, emergency operations, and exercises. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Data Retention, Return, and Deletion
Describes how retention periods, legal holds, return, deletion, and backup propagation are defined. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Data Safeguards, Access, and Approved Communications
Summarizes boundaries for access, event logging, support, and communication of sensitive information. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Document Control, Audit, and Continual Improvement
Describes the approval, review, audit, correction, and management-review cycle applied to the program. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Electronic Health Record Software Quality Seal Certificate
This entry presents an external validation issued by Chile's National Center for Health Information Systems (CENS) for an identified product and version. The certificate identifies PEGASI DE CHILE SPA as operator and PEGASI SAIL, version v1.97.128, as the evaluated software. It was issued in Santiago on December 18, 2025 and states validity through December 18, 2028.
- View document
Encryption, Key, and Secret Management
Summarizes requirements for encryption, certificates, keys, and secrets throughout their lifecycle. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Event Logging, Monitoring, and Escalation
Describes logging principles, protection of data in logs, monitoring, alerts, and escalation. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
HIPAA Health-Information Safeguards and Risk Management
Summarizes applicability, BAA agreements, minimum necessary, rights, risk analysis, contingency, and breaches under the HIPAA framework. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Identity, Authentication, and Access Control
Summarizes identity lifecycle, authentication, privileged access, service accounts, and periodic reviews. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Independent Health-Information Security Risk Assessment (2024)
This entry summarizes an Information Systems Security Report prepared for Pegasi International, Inc. by HIPAA for Humans following an independent security risk assessment. Michael Herrick served as lead risk analyst, and the report is dated March 27, 2024. The assessment examined business processes and information technology infrastructure related to storing, transmitting, and protecting electronic Protected Health Information (ePHI).
- View document
Information Security Program
Summarizes the objectives, principles, and responsibilities of the information-security program. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Integrated Risk Management and Control Applicability
Summarizes how PEGASI identifies, treats, accepts, and reviews risks and determines applicable controls. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Integration and Interoperability Security
Describes design, connectivity, access, and traceability controls applicable to integrations and interoperability interfaces. This summary covers corporate rules applicable to CONNECT, IOB. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Network, Cloud, and Supply-Chain Security
Describes principles for secure connectivity, segmentation, cloud services, and technology-supplier risks. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Personal-Data Breaches and Notification Support
Summarizes detection, assessment, documentation, escalation, and controller support for a potential breach. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Physical, Device, and Workforce Security
Summarizes controls over facilities, equipment, media, remote work, and workforce changes. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Privacy by Design and Impact Assessments
Explains how changes are assessed before real data is used and when a PIA or DPIA is required. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Privacy Roles, Independence, and Oversight
Explains the responsibilities of the DPO, Legal, Security, Product, and the functions that make or execute decisions. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Processing Inventory and ROPA Maintenance
Explains how purposes, roles, categories, systems, recipients, regions, retention, and safeguards are recorded for each processing activity. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Program Governance, Scope, and Responsibilities
Presents the corporate scope, accountability lines, and interfaces of the security and privacy program. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Secure Development, Configuration, and Change Management
Describes how security requirements are incorporated into architecture, development, testing, configuration, changes, and releases. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Security Incident Response and Learning
Describes preparation, classification, response, evidence preservation, communication, and post-incident learning. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Sensitive and Health Data, Minimization, and Quality
Describes enhanced safeguards, minimization, quality, and identifiability-reduction techniques. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Suppliers, Subprocessors, and International Transfers
Explains due diligence, contracts, subprocessor changes, business associates, and territorial assessments. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Transparency, Notices, and Individual Rights
Summarizes the notice lifecycle, consent where applicable, and verifiable handling of individual-rights requests. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Vulnerability, Patch, and Security Testing Management
Summarizes vulnerability identification, prioritization, remediation, verification, and coordinated disclosure. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
- View document
Workforce Competence, Training, and Responsibilities
Summarizes training, rule acknowledgement, confidentiality, and workforce-lifecycle requirements. This summary covers corporate rules applicable to PEGASI, SAIL, CONNECT, IOB, Corporate Services. It is intended for customers, assessors, and other parties that need to understand PEGASI's approach without access to operating instructions, configurations, personal data, or restricted evidence.
Framework and control tags indicate a thematic relationship; they do not constitute a certification on their own.
