Trust & governance

Trust starts with being clear about what is ready and what is still being tested.

SIJILL is still under development. Security, access, audit and clinical-governance requirements are being worked through as part of that process. Formal claims will be made only when the relevant controls and validation are in place.

01

Clear product status

SIJILL is in active development, with staged pilot deployments underway. The current shipped development release is Sijill 0.33.0, build 58, ICU Automation Core. This website does not present planned controls as finished certifications or production guarantees.

02

Release validation is stated with its boundary.

Build 58 passed source-level, shared-model and deterministic ICU regression checks in the available validation environment. That is useful evidence of software discipline, but it is not presented as equivalent to production deployment validation.

Source28 files parsed
Shared ICU layerType-check passed
ICU fixtures12 / 12 passed
ArchiveValidated
Separate final stepNative production-environment compilation, signing, deployment, integration and institutional acceptance remain separate validation activities.
03

Governed clinical content

Calculators, pathways, evidence and microbiology material carry explicit content states. Formula-verified tools are separated from implementation-pending tools, governed evidence is separated from live discovery, and source or review metadata remains visible around clinical reference material.

Principle A user should be able to see where clinical content came from and how it was reviewed.
04

Institutional validation before scale

Before production use, security, identity, data retention, integrations, audit requirements and clinical governance need to be agreed with the institution and the relevant jurisdiction.

05

Data handling principles

Production deployments should be designed around minimum-necessary access, accountable use and clear separation between demonstration, simulation and patient data.

  • Least-privilege role design
  • Institution-controlled identity and access boundaries
  • Auditable user and workflow events
  • Defined retention and deletion requirements
  • Separation of demonstration or simulation data from production data
  • No patient-identifiable information through the public marketing website
06

Security and compliance

Access control, audit, data protection and compliance documentation are still being developed. Certifications and jurisdiction-specific compliance status should be treated as pending unless SIJILL publishes them directly.

  • Role and access-control design
  • Audit-event and accountability requirements
  • Data protection and retention controls
  • Secure integration and deployment setup
  • Independent review and compliance documentation before production use
Before productionHosting, encryption, backup, incident response, identity, audit, data residency and jurisdiction-specific requirements must be documented and validated with the institution.