Compliance & Trust
MediScans is built for organizations that live under audit scrutiny. Every record is immutable, every action is traced, and every change requires documented approval.
MediScans is architected around the SOC 2 Trust Service Criteria for Security, Availability, and Confidentiality. These are not policies written after the fact — they are hard-coded controls enforced at the function level.
Note: MediScans is not a certified SOC 2 Type II vendor. These controls are architected to align with SOC 2 criteria and support organizations that require demonstrable controls for their own compliance programs.
Logical access controls
Role-based access with admin, auditor, compliance_admin, and user tiers. Every privilege assignment is logged.
Authentication and provisioning
Invite-only onboarding. Users cannot self-register — all accounts require admin approval and are audit-logged.
Unauthorized access prevention
Backend functions enforce role checks before any privileged operation. Unauthorized attempts are logged with tamper flags.
System monitoring
All state-changing operations write append-only AuditEvent records with timestamps, actor IDs, and field-level change diffs.
Change management
Finalized records cannot be edited directly. All post-finalization changes require an Amendment Request with reviewer approval.
Risk monitoring
TamperAlert entity captures hash mismatches and unauthorized edit attempts in real time. Alerts are assigned and resolution-tracked.
The Audit Chain
You don't have to think about audit logging — it happens behind the scenes on every action. Here's what gets captured:
Item photographed & created
Who, timestamp, session ID
AI identification committed
Provider, confidence score, source
Value assigned
All pricing sources cited
Manual correction made
Old value → new value, reviewer
Record finalized & locked
SHA-256 snapshot hash
Amendment requested
Requester, reason, proposed diff
Amendment approved/rejected
Reviewer, timestamp, notes
Export performed
Type, record count, SHA-256 checksum
IRS & Grant Compliance
IRS Form 990 Schedule M requires nonprofits to describe noncash contribution programs including who received them, how they were valued, and whether valuations are independently substantiated. MediScans satisfies all three requirements automatically.
IRS Form 990
Schedule M noncash contribution documentation
Grant Audits
Complete item-level records for every batch
Donor Letters
Export FMV reports for donor acknowledgment
Board Reports
Aggregate valuations with confidence levels
Privacy
We do not sell, share, or aggregate your data. Here's exactly how your information is protected.
All data is stored in your account. We do not aggregate or share your inventory data with third parties.
Every record is exportable at any time in machine-readable JSON or CSV. Your data belongs to you.
All API calls and file uploads use TLS 1.2+. No unencrypted data paths exist in the platform.
Auditor role has read-only access. Scanner role cannot view compliance dashboards. Segments are enforced server-side.
Data access, correction, and deletion requests are tracked in the PrivacyRequest system with resolution logging.
Audit events are retained indefinitely for compliance. Personally identifiable fields can be redacted on data deletion request.