Zero-exposure transfer
Studies move directly from source to destination over an encrypted, access-controlled path. Data is never parked in, or routed through, systems that don't need to see it.
Connect a clinical institution on one side and a research institution on the other. Clinical institutions and hospitals send imaging for free; research institutions pay $1 per study. Aegis handles encryption, access control, metering, and audit, so neither side builds or maintains the hard parts.
Studies move directly from source to destination over an encrypted, access-controlled path. Data is never parked in, or routed through, systems that don't need to see it.
Sending is free for clinical institutions; research institutions are billed $1 per study delivered, totaled monthly. Every transfer is measured independently, verifiable by both parties, and resistant to over- or under-reporting.
A cryptographically chained record of every authorization, access, and delivery. Pass an audit by exporting it, not by reconstructing it.
Designed for deployment in HIPAA-regulated environments, with per-study envelope encryption and Business Associate Agreements in place.
Multi-gigabyte CT and MRI volumes are handled as single sealed studies, with integrity verified end to end on every transfer.
DICOM-native ingest and a clean REST API. Connect your PACS on one side, your analysis pipeline on the other, and we handle everything between.
Connect, release, deliver. The security, metering, and audit run underneath.
The clinical institution sends an imaging study to Aegis over an encrypted channel. It's sealed with a per-study key (AES-256).
Aegis authorizes a precise, time-bound, single-purpose handoff to the approved research institution, and meters it independently as it happens.
The authorized research institution receives the study, integrity-verified to the byte. Billing settles automatically; the audit trail is sealed.
The proprietary part is how we meter and verify a transfer without ever touching the payload. Everything around it is built on recognized standards, and you can run it yourself in the live demo.
TLS 1.2+ end to end. DICOM file ingest — single objects or a ZIP of a study, encrypted at the endpoint.
AES-256 per-study envelope encryption; keys destroyed on expiry.
Short-lived, scoped, single-purpose signed URLs: least-privilege and time-boxed.
SHA-256 checksum verified end to end on every study: sent equals received.
Append-only, hash-chained, exportable records: tamper-evident and WORM-capable.
Delivery measured independently of sender and receiver, never from self-reported volumes.
Operated within isolated, access-controlled cloud infrastructure: per-study key isolation, least-privilege access, and no imaging PHI in the application tier — the pixels stay ciphertext; routing identifiers are encrypted at rest.
Automatic, irreversible destruction on expiry or view limit, every disposal logged.
Walk through a release-to-destruction exchange, or talk to us about connecting your systems.
Request access