Trust & compliance

Everything you need to assess us as a supplier, in one place. Last updated [date]. Anything we have not answered here: [info@domain]

What LayonMed 3D does

LayonMed 3D imports volumetric image data, segments it, reconstructs and edits 3D geometry, measures it and exports it. It is delivered as a hosted service.

Validating the tool in your own process

You are responsible for validating the tool within your own quality management system and for the conformity of what you make with it.

We make that straightforward. Our Validation & Compliance Pack contains:

Request the Validation & Compliance Pack

Most tool vendors leave you to invent your own validation. We ship you one.

Security

Controls marked planned are not yet in place. We would rather tell you that than have you find out.

Hosting[provider][Switzerland / EEA region] only
Data location[Switzerland / EEA]. No processing or storage outside this area.
AuthenticationIndividual named accounts, each bound to a unique email address. No shared credentials.
Password storagescrypt key derivation (n=16384, r=8, p=1) with a unique 16-byte random salt per account. Passwords are never stored or logged in recoverable form.
Password policy[state the minimum length in force — see our note before publishing]
Session tokensGenerated with a cryptographic random source, stored only as a SHA-256 digest, time-limited, and compared in constant time. Sign-out revokes immediately.
Multi-factor authenticationPlanned — target [date]
Failed-login limitingPlanned — target [date]
Session isolationEach session runs in its own isolated host environment; case data is removed on teardown.
Encryption in transitTLS for all traffic; session media encrypted in transport.
Encryption at restPlanned — target [date]
Access logging & audit trailPlanned — target [date]
Rate limiting & request capsApplied to session creation, requests and upload size.
Backup & tested restore[state the schedule and the date of the last tested restore, or "planned — target [date]"]
Vulnerability managementThird-party components are inventoried and monitored against published advisories; corrective releases are issued and affected customers notified.
Penetration testing[last date, or "planned — target [date]"]
Security contact[security@domain]coordinated vulnerability disclosure policy

No third-party loading. LayonMed 3D loads no third-party code or content at runtime — no content delivery network, no third-party fonts, no analytics, no embedded widgets. Setting up the video connection does contact a public STUN server, and where a direct connection is not possible the encrypted video is carried by a TURN relay; both see your IP address and neither receives image or account data (see the privacy notice). The delivered application contains exactly two third-party components, both under permissive licences and both fully attributed: third-party software notices.

Data protection

RolesFor data you upload, you are the controller and we are the processor. A Data Processing Agreement must be in force before any upload.
Data Processing AgreementAvailable here, pre-signed by us
Sub-processorsListed here, with advance notice of any change you can subscribe to
Lawful basisYou are responsible for the lawful basis of the data you upload and for informing data subjects.
Impact assessmentThe DPIA is the controller's obligation, so it is yours. We assist by providing the processing and security information you need.
Breach notificationWe notify you without undue delay, with the information you need for your own notification. You notify the authority.
Retention & deletionPer the Data Processing Agreement. Guest session data is deleted at session end or within [24 hours].
Data minimisationWe ask you to upload pseudonymised data only — a case reference rather than a name.
IdentifiabilityWe make no anonymisation claim. Cross-sectional imaging of the head and face remains identifiable after header identifiers are removed. Such data is pseudonymised, never anonymous.
Privacy NoticeRead it here

The service

Version identificationThe running version and build are displayed in the application. You can always see what you are using.
Release notesPublished with every release, stating whether the change can affect computational output and what we recommend you re-verify.
Known anomaliesPublished with every release, stating plainly whether each can affect an output.
Change notificationAt least [30] days' notice before any change capable of affecting computational output.
Version pinningAvailable. Your environment stays on the version you accepted, so a service update cannot invalidate your validation. Ask for it in your Order Form.
CorrectionsA defect capable of producing an incorrect output is corrected without delay, with immediate notification identifying the affected versions and dates.
Declared accuracyNo accuracy figures are currently declared. You must establish the accuracy achieved in your own workflow. Reference datasets with declared true dimensions are provided to help you.
Availability[target, or "no availability commitment is given"]
StatusService status
Support[channel, hours, response targets]
Data exportOpen formats, at any time.

Common questions

Are you ISO 13485 certified?
No. We operate a documented software lifecycle — development and change control, release, verification, security and defect management — and we share summaries under confidentiality as part of the Validation & Compliance Pack.
Do you have a quality management system?
We operate documented procedures for the lifecycle activities listed above. They are not third-party certified. What matters for your own validation is what we can evidence, and that is what the pack contains.
Will you complete our supplier questionnaire?
Most of it is already answered in the Validation & Compliance Pack. Send us anything the pack does not cover and we will complete it.
Can we audit you?
Yes, by arrangement, remote or on site, subject to confidentiality.
Where is our data stored?
[Switzerland / EEA] only. Never outside.
Who are your sub-processors?
Listed here, with advance notice of any change.
Is patient data anonymised?
No, and we never claim it is. Imaging of the head and face remains identifiable after names are removed. We ask you to upload pseudonymised data and we minimise what we hold.
Who is controller and who is processor?
You are the controller of the data you upload; we are the processor. Our Data Processing Agreement sets this out.
Do we need a data protection impact assessment?
That is the controller's obligation, so it is yours. We provide the processing and security information you need to complete it.
What happens if you have a breach?
We notify you without undue delay with the information you need for your own notification. Our procedure is described in the pack.
How do you handle vulnerabilities?
We inventory and monitor third-party components, issue corrective releases, and operate a coordinated disclosure policy. Security contact: [security@domain].
How do we know which version we are using?
It is displayed in the application, and recorded in exported files and projects.
What happens when you update the service?
You get at least [30] days' notice of any change capable of affecting output, with release notes, the known-anomaly list and our recommended re-verification scope. With version pinning, your environment does not move until you accept.
Do you publish known defects?
Yes, with every release, stating plainly whether each can affect an output.
What accuracy do you guarantee?
None is currently declared. We provide reference datasets with declared true dimensions so you can establish the accuracy achieved in your own workflow — which is what your own validation requires in any case.
Do you have product liability insurance?
[Settle this wording before publishing — see the note in document 35.]
What are your third-party dependencies?
Two, in the delivered application: three.js and pako, both permissive and fully attributed. No third-party code or content is loaded at runtime; the video connection uses a public STUN server and, if needed, a TURN relay, which see your IP address only.
Can we run it on our own infrastructure?
LayonMed 3D is supplied as a hosted service. An on-premise deployment is a separate discussion — contact us.
What happens to our data if we leave?
You can export at any time in open formats. After termination we delete it in accordance with the Data Processing Agreement.

Legal documents

Company

[Full legal name], [legal form] · [address], Switzerland
Commercial register [number] · VAT [number]

General [info@domain] · Data protection [privacy@domain] · Security [security@domain]