SECURITY

Built for pharma scrutiny, and honest about where we are

RocketMSL handles scientific conversations between field medical teams and healthcare professionals. That is sensitive by definition. This page sets out how the platform protects it, what we hold today, and what we are still working towards.

WHERE WE STAND TODAY

What we hold, and what we don’t

StandardStatusNote
SOC 2 Type IIIN PROGRESSPlatform built to SOC 2 controls. Certification underway. We are not certified today.
GDPRIN PLACEGDPR-aligned processing. Standard Contractual Clauses and the UK IDTA used for transfers. DPA available on request.
ISO 27001NOT YETNot currently held.
HIPAA BAANOT YETRocketMSL is not designed to process patient-identifiable data. Where protected health information is processed on behalf of a covered entity, it is only under a Business Associate Agreement.
21 CFR Part 11IN PROGRESSAudit trail and record-integrity controls in place. Full validation not yet completed.
BIPA and state biometric lawIN PLACEVoiceprints processed only under separate explicit opt-in consent, with a published retention schedule.

We would rather tell you this now than at the end of a procurement cycle.

DATA PROTECTION

Controls in place today

ControlWhat it means
EncryptionAES-256 at rest, TLS in transit. Applies to recordings, transcripts and derived intelligence alike.
Tenant isolationEvery record is scoped to the licensing organisation. Isolation is enforced in the query, not only in the interface.
Role-based access controlEnforced at the API layer, not hidden in the UI. Super Admin, Admin, Manager, MSL and Viewer roles, configurable per deployment.
Audit trailPermission-gated and state-changing actions are written to an audit log with actor and timestamp.
HostingAmazon Web Services. Database, vector-search and cache components run inside our AWS environment.
Data residencyData is processed in the United States. For EEA and UK customers, transfers rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision.
AI

Your conversations do not train anyone’s model

  • Scientific content, transcripts and insights are not used to train foundation models. Content is submitted under a no-training configuration
  • Model outputs are grounded in your approved content. Where the platform cannot answer from approved material, it escalates rather than generating an answer
  • Scoring and knowledge assessments are decision-support for human review. They are not automated decisions with legal or similarly significant effects

Sub-processors

Sub-processorPurpose
Amazon Web ServicesCloud hosting and storage
OpenAIAI and LLM processing of audio and text

Changes to this list are notified in advance under our Data Processing Agreement.

Recording consent is captured before any scientific interaction is recorded, and it determines what happens next. With consent, the conversation is captured and analysed. Without it, the MSL completes a structured post-meeting record instead — the same intelligence, entered by hand.

  • Consent is captured per meeting, not once per HCP
  • The gate is enforced in the application, not by policy alone. Where consent is declined, no audio is captured and nothing is transmitted to any third party
  • Consent status is stored on the interaction record and visible in every downstream report
RETENTION

How long we keep things

DataRetention
Audio recordingsDeleted after analysis, per customer configuration — unless linked to a safety or pharmacovigilance signal requiring longer retention by law
Transcripts and derived insightsDuration of the customer relationship, plus up to 90 days
VoiceprintsDeleted within 30 days of consent withdrawal, and within three years of last interaction
Account dataDeleted within 90 days of account closure
PHARMACOVIGILANCE AND MLR

Signals are detected and routed, not buried in a transcript

Adverse events, product quality complaints, off-label questions and medical information requests are identified in the interaction record and routed into your own internal process. RocketMSL structures and escalates the signal; your approved workflow decides what happens next.

  • Adverse events
  • Product quality complaints
  • Off-label questions
  • Medical information requests

Routing is configured to your SOPs during implementation. We do not assume a process on your behalf.

ON REQUEST

What we can send your security team

  • Data Processing Agreement
  • Security architecture overview
  • Sub-processor list
  • Biometric data policy and retention schedule

Request documentation

Found something?

Report security issues to privacy@rocketmsl.com. We will keep you updated until the issue is resolved. We do not pursue researchers who report in good faith.

Talk to us before procurement does

We would rather answer your security team’s questions early than discover them late. Send us your questionnaire and we will work through it.

Get in touch