Agreement & Trust

Terms of Service & Compliance

These terms define the service boundaries, regulatory compliance frameworks, and trust standards between Sanafin and our enterprise partners.

Using Sanafin

Sanafin provides SaaS infrastructure to structure, deploy, and automate outcome-based healthcare contracts. Our platform combines outcome verification, contract logic and settlement instructions so that funders, manufacturers and care teams can execute outcome-conditional agreements. Funds committed under such agreements are held by a licensed custody partner, never by Sanafin.

Account & Access Rules

  • Authorized CredentialsUsers must maintain the confidentiality of all system credentials and API tokens.
  • Access ScopePlatform access is granted solely to configure contracts, integrate clinical data sources, and review verification and settlement records.

User Responsibilities

  • Accurate ThresholdsCustomers are responsible for specifying correct clinical metrics and verification logic in contract models.
  • Lawful Data SourcingYou must ensure all digital health data, laboratory results, or clinical evidence feeds are legally obtained.

Security Infrastructure

We secure customer systems and data through institutional-grade controls:

  • End-to-End EncryptionAll data is encrypted in transit using TLS 1.3 and at rest with AES-256 keys.
  • Role-Based Access (RBAC)Strict authentication rules govern access to contract rules, settlement records, and API credentials.
  • De-identification SinksClinical biomarker feeds are pseudonymized at the integration source to protect privacy.

Compliance & Governance

Our governance framework is aligned with leading national and global standards:

  • Regulatory AlignmentDesigned to meet the requirements of the Swiss Federal Act on Data Protection (FADP) and the GDPR.
  • Swiss Legal PrinciplesConditional commitments and contract triggers are modelled to reflect the Swiss Code of Obligations.
  • Audit-Ready LogsPlatform activity logs are designed for institutional SOC-2 compliance audits.

Acceptable Use

You agree not to bypass security configurations, introduce malicious code, reverse-engineer the contract execution compiler, or attempt to manipulate verification events. Any suspicious activity will result in immediate API suspension.

Risk Management & Fallbacks

We mitigate operational risks through clear contract safety valves and automated fallbacks. Every outcome-based contract structured on Sanafin includes explicit parameters to manage edge cases:

Exception Paths

Predefined logic handles missing data feeds, client dropouts, or temporary connection issues without locking funds.

Oracle Fallbacks

If primary digital health validation sources fail, secure human-review checkpoints resolve clinical disputes.

Custody of funds

Funds are routed only upon verified outcome confirmation, preventing unauthorized or early payout release.

Payment & custody terms

Platform fees are defined in executed Statements of Work (SOW) or Order Forms. Funds committed under an outcome-conditional contract are held by a licensed custody partner and are released or returned only according to the verified contract criteria. Sanafin is not a bank or payment institution and does not hold client funds.

Intellectual Property

Sanafin owns all proprietary software, databases, API designs, and interfaces. Open-source specifications, including the EDEN framework schema, are licensed separately under their respective MIT/standard open licenses.

Verification Transparency

Transparency is key to eliminating disputes. Sanafin publishes the mathematical algorithms used to verify outcomes and calculate time-value thresholds under the open-source EDEN framework. Payers and providers can inspect and run independent tests on the validation scripts to confirm correctness before deploying them to production.

Limitations of Liability

Sanafin is a software provider and is not a party to clinical treatment outcomes or care decisions. We do not provide medical or clinical advisory. To the maximum extent permitted by law, Sanafin is not liable for indirect, incidental, or consequential damages resulting from clinical data inaccuracies or verification source failures.

Termination

Either party may terminate platform access in accordance with SOW agreements. Upon termination, committed funds are released or returned by the custody partner according to the final verified contract status in the audit record.

Contact & Inquiries

For legal inquiries, terms compliance, or data security documentation, contact: hello@sanafin.tech