Children's clinical data, handled the way you would handle it.
You are being asked to put paediatric health information into someone else's system. That deserves a specific answer rather than a badge, so here is what we do, what we sign, and what we will send your procurement team if they ask.
Compliance at a glance
HIPAA
Compliant, and we sign a BAA with every clinic customer.
GDPR
Compliant, with a data processing agreement available.
FERPA
Aligned handling of student education records for school settings.
COPPA
Aligned handling for users under thirteen.
Data ownership
Your clinic owns its clinical data
This is the part that matters most and the part most vendors are vaguest about, so we will be blunt.
- Your data is yours. The clinical records your practice generates on eMazeBrain belong to your practice.
- You can export it at any time, including if you leave. There is no hostage-taking at the exit.
- We do not sell data. Not to advertisers, not to researchers, not to anyone.
- We do not train models on identifiable patient data. The program-building algorithm operates on the individual child's own assessment and performance.
- We do not market to your patients. Your families are your relationship, not a lead list.
Controls
How the data is protected
Encryption
Data is encrypted in transit and at rest.
Access control
Role-based access, so a provider sees their own caseload and nothing else. Administrative access is separated from clinical access.
Audit logging
Access to patient records is logged, so who saw what and when is answerable rather than assumed.
Backup and recovery
Regular backups with tested restoration, plus per-patient program backups you control yourself from the dashboard.
Hosting and residency
Hosted with a major cloud provider. Tell us your residency requirement and we will confirm in writing what we can meet.
Subprocessors
We maintain a list of the third parties involved in delivering the service and will provide it on request.
On certifications, honestly
We state HIPAA compliance, GDPR compliance, and FERPA and COPPA alignment because those describe how we operate. Where a formal third-party attestation such as SOC 2 is in progress rather than complete, we will tell you that directly rather than implying otherwise on a website. Ask us for our current status and you will get the real answer in writing.
Accessibility
Built to be usable, and documented
Accessibility is not optional for our buyers. School districts already work to ADA Title II, and providers receiving federal financial assistance are working towards WCAG 2.1 AA under the HHS Section 504 rule, with deadlines in 2027 and 2028 depending on organisation size.
- We target WCAG 2.1 Level AA across this website and the platform.
- An accessibility conformance report is available on request for procurement packs.
- Motion respects the operating system's reduced-motion preference — relevant for sensory-sensitive users.
- Colour is never the only carrier of meaning; status is always labelled as well as coloured.
Full detail on our accessibility statement.
For procurement
What we will send you
If your organisation needs paperwork before it needs a demo, ask and we will send it.
- Business Associate Agreement (BAA)
- Data Processing Agreement (DPA)
- Subprocessor list
- Accessibility conformance report
- Security overview documentation
- Written statement of data collected and why
Reporting a security issue. If you believe you have found a vulnerability, please email drhish@emazelabs.com with the detail. We will acknowledge, investigate, and keep you informed. Please do not disclose publicly until we have had a reasonable chance to fix it.