Skip to main content

Trust & Security · Architecture Specification

Security begins with knowing what the platform does — and what it deliberately does not do.

A precise explanation of Operative Signal's zero-cloud-ingestion architecture, cryptographic boundaries, authorization models, and hospital compliance safeguards.

Visual Topology

Data Boundary Map

On-Premises Data Boundary

How OS Node Keeps Video at its Source

Zero Cloud Video Upload
INSIDE HOSPITAL FIREWALL

Your Hospital Storage

NAS · PACS · Workstations · Towers

Original Video Never Moves

High-resolution recordings, patient records, and local file paths remain on your existing storage drives.

LOCAL DAEMON

OS Node

Software running on your server

Extracts Metadata Only

Indexes procedure type, duration, optics vendor, and local rights. Assigns a pseudonymous OS Video ID.

OPERATIVE SIGNAL

Discovery & Validation

Governed Network Coordination

Zero-Knowledge Feasibility

Evaluates cohort availability in the aggregate. No external party can browse or access your files without approval.

No Manual Video Uploads

Connect folders once. OS Node keeps catalog records synchronized automatically.

Keep Existing Storage

Works seamlessly with your current NAS, PACS, local drives, and endoscopy recording towers.

Institutional Sovereignty

Your hospital decides who may query, analyze, or validate models against your data.

1. Control Plane vs. Local Data Plane

The cloud control plane stores user accounts, organization memberships, permissions, project metadata, pseudonymous OS Video IDs, and append-only audit events. Original raw surgical video files remain physically on hospital NAS, PACS, or server storage and are never uploaded to Operative Signal managed cloud buckets.

2. Outbound-Only Agent Connectivity

OS Node operates as an on-premises daemon establishing outbound mutual TLS connections to the control plane. No inbound firewall ports are opened, and no external entities can initiate unsolicited connections into the hospital intranet.

3. Cryptographic OS Video & Case IDs

Assets are indexed using SHA-256 content-addressed fingerprints and pseudonymous OS Video IDs. Internal institutional directory paths, patient identifiers, and server IP addresses are stripped locally and never transmitted across the wire.

4. Server-Authoritative Access Control

All access tokens, permission grants, and Project Space memberships are validated by server-side authorization routines. Client-provided identifiers are never trusted autonomously.

5. Append-Only Governance & Audit Trails

Every policy modification, access authorization, and validation evaluation is recorded in an immutable ledger, providing health system compliance officers with full historical provenance.

6. Feature Maturity & Safety Constraints

Arbitrary third-party executable containers and patient-derived cloud uploads remain disabled in production by default. Governance checklists do not override institutional ethical review requirements.

Preparing an institutional IT / infosec review?

Our engineering team provides comprehensive architectural packets, threat models, and pilot deployment guides for hospital security officers.

Request Hospital Pilot Pack