Loading standards & compliance…
Standards and compliance
This page is the register, not the brochure. Every status below is the label its registry carries today, every total is counted from that registry at build time, and the vocabulary that separates an audited fact from an engineering intention is defined before anything claims either.
A status is never upgraded to sound better than the record. If an assessment is engaged but unissued, it says engaged.
How to read this page
Compliance pages usually blur certification, alignment, and intention into one reassuring adjective. These five terms are used strictly, and each status pill on this page resolves to exactly one of them.
An external assessor has issued an attestation or certificate and the artefact is on file today. Available to a prospective customer under NDA.
An assessment is formally engaged or evidence collection is under way. No certificate exists yet, and none is implied.
Committed on the roadmap with an owner assigned. Work has not started. This is an intention, not a control.
Platform controls are built to a published standard and the mapping is documented, with gaps recorded. This is not a certification and is never presented as one.
The standard is tracked for awareness. No alignment work is claimed.
Independent review
Every attestation MedXline holds, is pursuing, or has explicitly decided not to pursue — including the ones that are still empty. A register that only lists wins is a marketing asset, not a register.
Internal controls over financial reporting (ICFR) for the HIC ledger, payment intent state machine, MoMo settlement reconciliation, and payout disbursement workflows.
Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy) covering the Next.js platform, Postgres tenant data plane, payment orchestration, and identity stack.
Information Security Management System covering all production cloud workloads, the engineering org, and supporting business processes (HR, vendor management, change management).
Privacy Information Management System extension to the 27001 ISMS, covering processing of patient PHI, member PII, and partner financial PII across all jurisdictions of operation.
Statutory data controller registration under the Data Protection Act 2012 (Act 843) covering MedXline Ghana operations including patient records, payment data, and KYC data.
Black-box + grey-box pentest of the Next.js public surface (auth, payments, partner portal, compliance console), authenticated APIs, and the cloud infrastructure perimeter (Vercel + Supabase + Upstash).
Card payment integration scope: tokenization via gateway, no PAN storage, partner-mediated card-on-file. Mobile money rails (MTN MoMo) are out of PCI scope.
Deferred until US healthcare expansion. Tracked here so the option remains visible in governance reviews; do not represent as in-scope to customers.
Standards alignment
Alignment means controls are mapped to a published standard with the gaps written down. It is a weaker claim than certification, and it is stated as the weaker claim throughout.
Open the conformity matrixInternational standard for an Information Security Management System (ISMS) — risk-based controls covering organisation, people, processes, and technology.
Reporting framework on controls relevant to Security, Availability, Confidentiality, Processing Integrity, and Privacy of a service organisation.
Reporting framework on controls relevant to user entities' Internal Control over Financial Reporting (ICFR).
Health-sector application of ISO/IEC 27002 — security management in health using ISO/IEC 27002 controls.
Standards-based, Machine-readable, Adaptive, Requirements-based, Testable — WHO's framework for digital adaptation kits in health systems.
AI Management System — requirements for establishing, implementing, maintaining and continually improving an AI management system within an organisation.
AI Risk Management Framework — voluntary guidance to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.
Ethics and governance of artificial intelligence for health — six principles ensuring AI works to the public benefit of all countries.
African Union Convention on Cyber Security and Personal Data Protection — continental instrument harmonising data protection and cybersecurity.
Continental policy framework governing data, cross-border flows, and digital trade across African Union member states.
ECOWAS Supplementary Act on Personal Data Protection — regional instrument governing data processing across West African member states.
Model law adopted by SADC to harmonise data-protection rules across Southern African states.
Continental protocol on digital trade — common rules for cross-border digital trade, payments, and data flows across AfCFTA members.
Statutory data protection law in Ghana; controllers and processors must register with the Data Protection Commission.
Protection of Personal Information Act — South Africa's primary data protection statute; requires Information Officer registration.
Nigeria Data Protection Act, 2023 — established the Nigeria Data Protection Commission; recognises lawful bases including contract, legal obligation, and vital interests.
Kenya Data Protection Act 2019 — health data treated as sensitive personal data; cross-border transfer constraints and data-localisation expectations.
Coverage by continent
A platform built for international deployment should be able to say which parts of the world it has actually assessed. Each continent below reports what is on file — country records, jurisdiction rule packs, published readiness assessments — or states plainly that nothing is.
Open the regional readiness hubJurisdiction register
97 jurisdictions across 6 continents, each recording the national data-protection statute as enacted, the authority that administers it, and whether that authority is operational. 66 have a statute in force and enforced; the rest are enacted-but-dormant, pending, or absent, and are marked as such.
Open the African country matrixThe second-largest continent; 54 African Union member states across six regional blocs. The only continent with a per-country page and a rollout-wave programme.
The largest continent by size and population; includes East, South, Southeast, Central, and West Asia.
Western Asia5 jurisdictions
Eastern Asia3 jurisdictions
Southern Asia1 jurisdiction
South-Eastern Asia6 jurisdictions
The western peninsula of the Eurasian landmass; borders Asia and the Mediterranean.
Union-wide instruments1 jurisdiction
Western Europe4 jurisdictions
Northern Europe4 jurisdictions
Southern Europe2 jurisdictions
Eastern Europe1 jurisdiction
The northern landmass of the Americas; includes the US, Canada, Mexico, and Central American and Caribbean areas.
Northern America2 jurisdictions
Central America3 jurisdictions
The southern landmass of the Americas; includes 12 sovereign nations.
South America7 jurisdictions
The island and continental region including Australia, New Zealand, and the Pacific island groups of Melanesia, Micronesia, and Polynesia.
Australia and New Zealand2 jurisdictions
Melanesia2 jurisdictions
The southernmost, ice-covered land division, with no sovereign countries and therefore no jurisdiction rows.
Go deeper
These are not summaries written for this page. Each one renders the same compiled-in records, so a figure quoted in one place cannot disagree with the same figure quoted in another.
Cross-mapping
Every regulatory framework against the standards declared for it and the attestations that cover it. The place to check whether a claim actually closes an obligation.
OpenAudit roadmap
Every active, engaged, planned, and explicitly not-pursued attestation, with scope, accountable owner, and renewal cadence.
OpenAI governance
How assistive intelligence is bounded: pre-release gates, prompt and tool-abuse defences, human review points, and per-region enablement.
OpenRegression bar
Published budgets per intent, the latest archived run, and pass or fail per metric — surfaced from the evaluation artefacts in this repository.
OpenSecurity findings
Severity-to-remediation SLA matrix, finding-status workflow, and live counts. Breaches of the SLA fail the build.
OpenIdentity assurance
Document and liveness checks, sanctions screening, address resolution, and three-band decisioning with a human reviewer in the loop.
OpenForward schedule
Upcoming compliance events derived from the certifications registry, with anything overdue pinned to the top.
OpenChange feed
Atom feed and optional email digest for registry changes, with a published SHA-256 fingerprint so you can verify you are reading the same record we are.
OpenAsk directly
Answers are drawn from the published compliance registry. When your device supports it the model runs in your browser and no question leaves the machine; otherwise the same answers come from the built-in FAQ, which works offline once this page has loaded.
Bring the assessment
We will answer it against this register — marking each line as attested, aligned, configurable, externally dependent, or not yet done. Including the lines where the answer is no.