Children's clinical data, handled the way you would handle it.

You are being asked to put paediatric health information into someone else's system. That deserves a specific answer rather than a badge, so here is what we do, what we sign, and what we will send your procurement team if they ask.

Compliance at a glance

HIPAA

Compliant, and we sign a BAA with every clinic customer.

GDPR

Compliant, with a data processing agreement available.

FERPA

Aligned handling of student education records for school settings.

COPPA

Aligned handling for users under thirteen.

Data ownership

Your clinic owns its clinical data

This is the part that matters most and the part most vendors are vaguest about, so we will be blunt.

  • Your data is yours. The clinical records your practice generates on eMazeBrain belong to your practice.
  • You can export it at any time, including if you leave. There is no hostage-taking at the exit.
  • We do not sell data. Not to advertisers, not to researchers, not to anyone.
  • We do not train models on identifiable patient data. The program-building algorithm operates on the individual child's own assessment and performance.
  • We do not market to your patients. Your families are your relationship, not a lead list.

Controls

How the data is protected

Encryption

Data is encrypted in transit and at rest.

Access control

Role-based access, so a provider sees their own caseload and nothing else. Administrative access is separated from clinical access.

Audit logging

Access to patient records is logged, so who saw what and when is answerable rather than assumed.

Backup and recovery

Regular backups with tested restoration, plus per-patient program backups you control yourself from the dashboard.

Hosting and residency

Hosted with a major cloud provider. Tell us your residency requirement and we will confirm in writing what we can meet.

Subprocessors

We maintain a list of the third parties involved in delivering the service and will provide it on request.

On certifications, honestly

We state HIPAA compliance, GDPR compliance, and FERPA and COPPA alignment because those describe how we operate. Where a formal third-party attestation such as SOC 2 is in progress rather than complete, we will tell you that directly rather than implying otherwise on a website. Ask us for our current status and you will get the real answer in writing.

Accessibility

Built to be usable, and documented

Accessibility is not optional for our buyers. School districts already work to ADA Title II, and providers receiving federal financial assistance are working towards WCAG 2.1 AA under the HHS Section 504 rule, with deadlines in 2027 and 2028 depending on organisation size.

  • We target WCAG 2.1 Level AA across this website and the platform.
  • An accessibility conformance report is available on request for procurement packs.
  • Motion respects the operating system's reduced-motion preference — relevant for sensory-sensitive users.
  • Colour is never the only carrier of meaning; status is always labelled as well as coloured.

Full detail on our accessibility statement.

For procurement

What we will send you

If your organisation needs paperwork before it needs a demo, ask and we will send it.

  • Business Associate Agreement (BAA)
  • Data Processing Agreement (DPA)
  • Subprocessor list
  • Accessibility conformance report
  • Security overview documentation
  • Written statement of data collected and why

Reporting a security issue. If you believe you have found a vulnerability, please email drhish@emazelabs.com with the detail. We will acknowledge, investigate, and keep you informed. Please do not disclose publicly until we have had a reasonable chance to fix it.