Trust Centre

1. Overview

Mosaic Health AI is designed for healthcare communications teams that need to create high-quality, compliant scientific content.

We take security, privacy, and ethical AI use seriously – ensuring every automation remains transparent, traceable, and under human control.

Our approach follows three core principles:

  • Security by Design – protection built in from day one.
  • Privacy by Default – data minimised and encrypted throughout.
  • Human Oversight – AI enhances, never replaces, expert review.

2. Our Security Principles

We protect data through layered, proactive measures based on global standards.

PrincipleDescription
Least PrivilegeUsers only access what they need for their role.
Encryption EverywhereTLS 1.2+ for data in transit; AES-256 for data at rest.
TransparencyClients can request documentation on data handling and subprocessors.
Continuous ReviewPolicies updated regularly as the platform evolves.

3. Data Protection & Privacy

Data Ownership

All data uploaded to Mosaic remains the property of the client. Mosaic processes data solely to provide platform functionality during the pilot.

Data Residency

Data is stored within the UK/EU region via Render (on AWS infrastructure).

Encryption

  • In transit: TLS 1.2+
  • At rest: AES-256

Data Retention

Data is deleted within 30 days of pilot completion or on request.

Subprocessors

VendorFunctionCertifications
Render (AWS)Hosting and infrastructureSOC 2, ISO 27001
OpenAILarge Language Model providerSOC 2 Type II, ISO 27001
PineconeVector databaseISO 27001
Google WorkspaceCollaboration toolsSOC 2, ISO 27001

Client data is never used to train or fine-tune AI models.

4. Information Security Controls

Access Control

  • Role-Based Access Control (RBAC)
  • MFA for admin access
  • Regular access reviews

Network Security

  • HTTPS enforced across all endpoints
  • API tokens with expiry and scoped permissions

Incident Response

  • Based on NIST framework
  • Incidents triaged and contained within 4 business hours
  • ICO notified within 72 hours if required

Backup & Recovery

  • Cloud-native encrypted backups
  • Tested restoration procedures

Downloadable Policies

  • Information Security Policy
  • Encryption Policy
  • Data Handling Policy
  • Incident Response Policy
  • Third-Party Access Policy

5. Compliance & Governance

Mosaic aligns with major international frameworks:

StandardStatus
ISO 27001Principles adopted
SOC 2Principles adopted
UK/EU GDPRFully compliant
EU AI ActReady
NIST CSFPartial alignment

6. Responsible AI Use

Our AI practices focus on transparency, traceability, and human control.

Key Principles

  • Human-in-the-loop: All Mosaic outputs are reviewed before use.
  • Transparency: AI-generated drafts are auditable and reference-linked.
  • Ethical Boundaries: Mosaic does not process personal health data or make clinical decisions.
  • Third-Party Models: We use OpenAI's GPT models via API — never trained or fine-tuned on client data.
  • Governance: We adhere to EU AI Act principles for documentation and accountability.

Read our AI Transparency Statement

7. Monitoring & Improvement

  • Real-time monitoring of access logs and system uptime.
  • Regular dependency updates and security patches.
  • Security and privacy reviews at least twice yearly.
  • Team-wide infosec training and incident simulation exercises.

8. Insurance & Accountability

Mosaic maintains appropriate insurance coverage for the pilot phase:

TypeCoverage
Professional Indemnity£10,000,000
Public Liability£5,000,000
Cyber Liability£2,000,000
Employer's£10,000,000

Certificates available upon request.

10. FAQs

Q: Where is my data stored? A: Data is stored in the UK/EU region using Render on AWS infrastructure.

Q: Is my data used to train AI models? A: No. Client data is never used to train, fine-tune, or improve any AI model.

Q: What happens if there is a data breach? A: Mosaic follows a NIST-based Incident Response Plan, with ICO notification readiness within 72 hours.

Q: Can I get a copy of your security policies? A: Yes, summary PDFs are available on request under NDA.

Q: Are you compliant with the EU AI Act? A: Mosaic is classified as a low-risk system under the AI Act and meets all transparency and human oversight requirements.


Last updated: March 2026 © 2025 Mosaic Health AI Ltd – Registered in the United Kingdom

We continuously improve our security posture and update this Trust Centre accordingly.

Built for trust

We take security, privacy, and ethical AI very seriously – ensuring every automation remains transparent, traceable, and under human control.

Secure by Design

We follow ISO 27001 and SOC 2 principles and maintaining clear data-handling and incident-response policies.

Privacy by Default

Data minimised and encrypted throughout, with all data encrypted in transit (TLS 1.2+) and at rest (AES-256).

Human Oversight

We make sure that AI enhances, never replaces, expert review.

See Mosaic in action

We're working with select health-comms partners to assess Mosaic's operational impact and develop new features.

If you'd like early access, get in touch to join the pilot program.

Book a demo

Not ready for a demo yet? Get in touch to learn how Mosaic can help improve productivity and quality of your medical communications.