ledger 2026-09-28T02:23:32.097Z · evidence sha256 cf7a21b4825fea7db42a4f51a44b22e7615a4b21cfe655bb2892c02fd0c2bcd0 · full ledger (JSON) · claims (JSON)
Operational state
Derived per subsystem. There is no global "all systems operational" statement.
CIRE runtime and calibration jobs
DEGRADED- What exists
- CIRE 2.0 runs on every inference in the request path; daily jobs recompute calibration profiles and re-run reference self-conformance.
- Current state
- cire-calibration: the latest scheduled run failed (21 consecutive failures). cire-reference-certification: the last 21 scheduled runs succeeded.
- Evidence
- Production database records · EV-SYS-CIRE-20260927 (sha256 0f252f2d27c2da42…)
- Last verified
- 2026-09-27T03:20:19.103+00:00
- Limitations
- CIRE signals are structural and policy states; they are not clinical accuracy.
- Activation requirement
- Each scheduled CIRE job needs 3 consecutive successful scheduled runs. cire-calibration also needs a registered production champion model; without one it records SUCCESS_NO_ELIGIBLE_DATA.
Outcome calibration materialization
NO DATA- What exists
- A daily job materializes confirmed, non-synthetic outcomes into append-only calibration buckets per tenant, label, species, and model version.
- Current state
- outcome-calibration-materialization: no scheduled run has been recorded.
- Evidence
- Production database records · EV-SYS-OUTCOME-MATERIALIZATION-20260928 (sha256 56dd2db3fcea2afc…)
- Last verified
- Never
- Limitations
- Calibration is tenant-local. It does not retrain or update model weights.
- Activation requirement
- 3 consecutive scheduled runs must materialize confirmed outcomes.
Network learning (federation)
NO DATA- What exists
- Federation substrate: enrollment, masked contribution commitments, round scheduling, and benchmark/calibration gates.
- Current state
- NETWORK NOT ACTIVE: 0 production participants (minimum 2).
- Evidence
- Production database records · EV-SYS-NETWORK-LEARNING-20260928 (sha256 39c3e0a36b61223e…)
- Last verified
- 2026-09-28T02:23:32.097Z
- Limitations
- A network with fewer than two authorized participating clinics learns nothing across tenants.
- Activation requirement
- At least 2 authorized participating clinics.
Developer platform
NO DATA- What exists
- A versioned partner API contract with 10 endpoints, hashed scoped API keys, quota metering, and usage analytics.
- Current state
- Partner API contract is implemented; no products are currently published.
- Evidence
- Production database records · EV-SYS-DEVELOPER-PLATFORM-20260928 (sha256 1e7c8e728961f1f0…)
- Last verified
- 2026-09-28T02:23:32.097Z
- Limitations
- Partner access is provisioned manually after onboarding review.
- Activation requirement
- Publish at least one API product.
Partner API (/api/v1)
NO DATA- What exists
- The /api/v1 partner contract at https://www.vetios.tech/api/v1, authenticated with Bearer vios_k1_ keys.
- Current state
- No partner API calls were recorded in the last 7 days.
- Evidence
- Production database records · EV-SYS-PARTNER-API-20260928 (sha256 2f391f47c72bab31…)
- Last verified
- Never
- Limitations
- Operational status is inferred from recorded partner calls; with no calls there is no evidence either way.
- Activation requirement
- An authorized partner must call the API.
ProofLoop public verification artifact
OPERATIONAL- What exists
- A public, signed ProofLoop artifact and an independent verifier that runs without VetIOS systems.
- Current state
- The public artifact verifies: receipt integrity, evidence digests, signature, eval binding, and gate result.
- Evidence
- Recorded artifact · EV-SYS-PROOFLOOP-20260928 (sha256 6481dfa4b7997b61…)
- Last verified
- 2026-09-28T02:23:32.097Z
- Limitations
- The published artifact is synthetic. It proves the verification mechanism, not clinical performance.
- Activation requirement
- None: requirements are met.
Edge nodes
NO DATA- What exists
- Edge node registration, device credentials, heartbeats, and sync jobs.
- Current state
- No edge nodes are registered as online.
- Evidence
- Production database records · EV-SYS-EDGE-20260928 (sha256 54a4d77a31d9c8dd…)
- Last verified
- 2026-09-28T02:23:32.097Z
- Limitations
- No edge node runs clinical inference offline in production today unless counted below.
- Activation requirement
- A clinic edge node must register and send heartbeats.
Public model registry
NO DATA- What exists
- A model registry with governance gates and read-only public model cards.
- Current state
- No public model cards are published.
- Evidence
- Production database records · EV-SYS-MODEL-REGISTRY-20260928 (sha256 3b6fb118e4bfd2f1…)
- Last verified
- 2026-09-28T02:23:32.097Z
- Limitations
- The production clinical engine is a deterministic, versioned rule system; it has no trained weights to publish a card for unless listed.
- Activation requirement
- Promote a model version through governance and publish its card.
Clinical validation
What confirmed outcomes and independent studies support. Structural CIRE signals are never counted here.
Reliability thresholds are implemented; no clinical slice is VALIDATED_FOR_SLICE. Across every tenant's latest calibration run, 15 tenant, model, and species slice(s) hold at least one confirmed outcome label, and none meets the minimum evidence. This is a different scope from the public evidence tenant's activity counts.
evidence: Production database records · EV-CLINICAL-RELIABILITY-VALIDATED-SLICES-20260928 · observed 2026-09-28T02:23:32.097Z · valid until 2026-09-29T04:23:32.097Z · freshness daily_cron_proof_26h
No independent clinical validation has been completed.
evidence: External validation record · EV-CLINICAL-EXTERNAL-VALIDATION-20260928 · freshness explicit_review_date
NO DATA: outcome-calibration-materialization: no scheduled run has been recorded.
evidence: Production database records · EV-OUTCOME-LEARNING-OPERATIONAL-20260928 · freshness daily_cron_proof_26h
Learning
Three mechanisms, never used interchangeably.
Learning today is tenant-local calibration only. There is no active cross-tenant learning and no model weight update.
evidence: Production database records · EV-NETWORK-LEARNING-MECHANISM-20260928 · observed 2026-09-28T02:23:32.097Z · valid until 2026-09-28T02:28:32.097Z · freshness network_participants_5m
Tenant-local calibration is implemented: confirmed outcomes adjust that tenant's displayed confidence only. No calibration run has been recorded in the last 30 days.
evidence: Production database records · EV-LEARNING-TENANT-LOCAL-CALIBRATION-20260928 · freshness daily_cron_proof_26h
Cross-tenant aggregate learning is implemented but inactive: no active federation.
evidence: Production database records · EV-LEARNING-CROSS-TENANT-AGGREGATE-20260928 · observed 2026-09-28T02:23:32.097Z · valid until 2026-09-28T02:28:32.097Z · freshness network_participants_5m
Outcomes do not update model weights. The production clinical engine (clinical_deterministic_multisystem_v1) is a deterministic, versioned rule system.
evidence: Recorded artifact · EV-LEARNING-MODEL-WEIGHT-UPDATE-20260928 · freshness static_artifact_per_deploy
Federation substrate implemented; no active production federation (0 participants, minimum 2).
evidence: Production database records · EV-FEDERATION-NETWORK-ACTIVE-20260928 · observed 2026-09-28T02:23:32.097Z · valid until 2026-09-28T02:28:32.097Z · freshness network_participants_5m
0 production federation participants.
evidence: Production database records · EV-NETWORK-PARTICIPANT-COUNT-20260928 · observed 2026-09-28T02:23:32.097Z · valid until 2026-09-28T02:28:32.097Z · freshness network_participants_5m
CIRE
Runtime health of CIRE and the verification level of its reference implementation.
DEGRADED: cire-calibration: the latest scheduled run failed (21 consecutive failures). cire-reference-certification: the last 21 scheduled runs succeeded.
evidence: Production database records · EV-CIRE-OPERATIONAL-20260927 · observed 2026-09-27T03:20:19.103+00:00 · freshness daily_cron_proof_26h
The reference CIRE engine passes the published conformance fixture at level SELF_CONFORMANCE. It has no reviewer, third-party, or clinical verification.
evidence: Automated tests and CI configuration · EV-CIRE-CONFORMANCE-LEVEL-20260928 · freshness static_artifact_per_deploy
Release gates and verification
Evidence anyone can re-run, with the signing key anchored in a public transparency log outside vetios.tech.
OPERATIONAL: The public artifact verifies: receipt integrity, evidence digests, signature, eval binding, and gate result.
evidence: Recorded artifact · EV-PROOFLOOP-REPLAY-VERIFIED-20260928 · observed 2026-09-28T02:23:32.097Z · freshness static_artifact_per_deploy
Every pull request to main runs: lint and typecheck; web unit tests, including the canonical API contract, SDK, trust ledger, and route manifest; API auth surface; egress surface; RLS policy surface; dependency audit; CSP boundaries; production dev-bypass guard; generated OpenAPI artifacts; CIRE fixtures, conformance, and independent formula; public CIRE examples; engine-generated clinical showcase; public claim consistency; ProofLoop artifact verifier; database migrations replayed and verified in a disposable Supabase Postgres (schema invariants, rollbacks, apply bundles). Whether a failing run blocks the merge depends on repository branch protection, which is not published here.
evidence: Automated tests and CI configuration · EV-SECURITY-RELEASE-GATES-20260928 · freshness static_artifact_per_deploy
API and platform
The partner contract, its origin, and what is published.
The canonical partner API is https://www.vetios.tech/api/v1.
evidence: Recorded artifact · EV-API-CANONICAL-ORIGIN-20260928 · freshness static_artifact_per_deploy
api.vetios.tech is not in service (no DNS record). Use https://www.vetios.tech/api/v1.
evidence: Runtime probe · EV-API-DEDICATED-ORIGIN-20260928 · observed 2026-09-28T02:23:32.097Z · freshness live_catalog_1h
NO DATA: No partner API calls were recorded in the last 7 days.
evidence: Production database records · EV-PARTNER-API-OPERATIONAL-20260928 · freshness partner_api_usage_7d
Outbox delivery uses a dedicated, least-privilege credential; the current one expires 2026-12-26.
evidence: Production database records · EV-OUTBOX-SERVICE-CREDENTIAL-20260928 · observed 2026-09-28T02:23:32.097Z · valid until 2026-09-28T03:23:32.097Z · freshness live_catalog_1h
Partner API contract is implemented; no products are currently published.
evidence: Production database records · EV-DEVELOPER-PRODUCTS-PUBLISHED-20260928 · observed 2026-09-28T02:23:32.097Z · valid until 2026-09-28T03:23:32.097Z · freshness live_catalog_1h
No public model cards are published.
evidence: Production database records · EV-MODEL-CARDS-PUBLIC-COUNT-20260928 · observed 2026-09-28T02:23:32.097Z · valid until 2026-09-28T03:23:32.097Z · freshness live_catalog_1h
No edge nodes are online.
evidence: Production database records · EV-EDGE-ACTIVE-NODES-20260928 · observed 2026-09-28T02:23:32.097Z · valid until 2026-09-28T03:23:32.097Z · freshness live_catalog_1h
No external uptime monitor is configured, so VetIOS publishes no uptime figure. The public /api/health reports liveness only; dependency health is available to operators.
evidence: Runtime probe · EV-PLATFORM-UPTIME-20260928 · freshness static_artifact_per_deploy
Integrations
Vendor names describe adapter compatibility only. Adapter existence, vendor approval, clinic connection, and partnership are tracked separately and never inferred from one another.
Adapter implementation for IDEXX, tested with synthetic payloads; vendor authorization required. It uses the generic lab-result normalizer; there is no IDEXX-specific API client.
- Adapter exists
- yes
- Vendor approval
- none recorded
- Clinic connection
- none
- Partnership
- none
Production connectivity requires: vendor authorization; an active production connection with a credential reference hash; a successful production authorization handshake; at least one successful sync run that ingested normalized events; a successful sync within the last 24 hours.
Adapter implementation for Antech; vendor authorization required. It uses the generic lab-result normalizer; there is no Antech-specific API client.
- Adapter exists
- yes
- Vendor approval
- none recorded
- Clinic connection
- none
- Partnership
- none
Production connectivity requires: vendor authorization; an active production connection with a credential reference hash; a successful production authorization handshake; at least one successful sync run that ingested normalized events; a successful sync within the last 24 hours.
Adapter implementation for ezyVet, tested with synthetic payloads; vendor authorization required. It uses the generic workflow normalizer; there is no ezyVet-specific API client.
- Adapter exists
- yes
- Vendor approval
- none recorded
- Clinic connection
- none
- Partnership
- none
Production connectivity requires: vendor authorization; an active production connection with a credential reference hash; a successful production authorization handshake; at least one successful sync run that ingested normalized events; a successful sync within the last 24 hours.
Adapter implementation for AVImark; vendor authorization required. It uses the generic workflow normalizer; there is no AVImark-specific API client.
- Adapter exists
- yes
- Vendor approval
- none recorded
- Clinic connection
- none
- Partnership
- none
Production connectivity requires: vendor authorization; an active production connection with a credential reference hash; a successful production authorization handshake; at least one successful sync run that ingested normalized events; a successful sync within the last 24 hours.
Adapter implementation for Cornerstone; vendor authorization required. It uses the generic workflow normalizer; there is no Cornerstone-specific API client.
- Adapter exists
- yes
- Vendor approval
- none recorded
- Clinic connection
- none
- Partnership
- none
Production connectivity requires: vendor authorization; an active production connection with a credential reference hash; a successful production authorization handshake; at least one successful sync run that ingested normalized events; a successful sync within the last 24 hours.
Adapter implementation for Covetrus, tested with synthetic payloads; vendor authorization required. It uses the generic workflow normalizer; there is no Covetrus-specific API client.
- Adapter exists
- yes
- Vendor approval
- none recorded
- Clinic connection
- none
- Partnership
- none
Production connectivity requires: vendor authorization; an active production connection with a credential reference hash; a successful production authorization handshake; at least one successful sync run that ingested normalized events; a successful sync within the last 24 hours.
Adapter implementation for Smart Flow; vendor authorization required. It uses the generic workflow normalizer; there is no Smart Flow-specific API client.
- Adapter exists
- yes
- Vendor approval
- none recorded
- Clinic connection
- none
- Partnership
- none
Production connectivity requires: vendor authorization; an active production connection with a credential reference hash; a successful production authorization handshake; at least one successful sync run that ingested normalized events; a successful sync within the last 24 hours.
Data governance
The same model the privacy policy renders.
Data at rest: Supabase (Postgres, Auth, Storage) in AWS Europe (Ireland), eu-west-1 (observed 2026-09-15). Application processing: Vercel (serverless functions for the web app and API) in Vercel iad1, Washington, D.C., USA (AWS us-east-1) (observed 2026-09-26). Requests are processed in United States and data is stored in Ireland (EU), so clinical data submitted to VetIOS crosses between those jurisdictions. Content sent to external AI model providers is processed on their infrastructure, whose location VetIOS has not verified.
evidence: Recorded artifact · EV-DATA-RESIDENCY-20260915 · observed 2026-09-15T22:57:39.837Z · valid until 2026-12-14T22:57:39.837Z · freshness infrastructure_observation_90d
VetIOS user accountvetios_account+
Name, email, and authentication identity of clinic staff and operators who sign in to VetIOS.
- Controller
- VetIOS, which decides the purposes and means.
- Processor
- VetIOS, with the sub-processors listed in the privacy policy.
- Storage
- Data at rest: Supabase (Postgres, Auth, Storage) in AWS Europe (Ireland), eu-west-1 (observed 2026-09-15). Supabase Auth.
- Retention
- Kept until a deletion request is executed. There is no automated retention or purge job.
- Training use
- Never.
- Secondary use
- Shared validation: never. Research: never. Federation: never. Population intelligence: never.
- Erasure
- Hard-deleted on request.
- Consent
- Account terms.
- Cross-border transfer
- Requests are processed in United States and data is stored in Ireland (EU), so clinical data submitted to VetIOS crosses between those jurisdictions. Content sent to external AI model providers is processed on their infrastructure, whose location VetIOS has not verified.
Login, security, and fraud recordssecurity_telemetry+
Sign-in events, rate-limit and abuse signals, credential use, and security incident records.
- Controller
- VetIOS, which decides the purposes and means.
- Processor
- VetIOS, with the sub-processors listed in the privacy policy.
- Storage
- Data at rest: Supabase (Postgres, Auth, Storage) in AWS Europe (Ireland), eu-west-1 (observed 2026-09-15).
- Retention
- Kept until a deletion request is executed. There is no automated retention or purge job.
- Training use
- Never.
- Secondary use
- Shared validation: never. Research: never. Federation: never. Population intelligence: never.
- Erasure
- Not deleted: Security and fraud prevention (pending counsel review of the exact legal basis). On request, the identity link is removed, the payload is minimized, the legal basis is recorded, and processing is limited to: security investigation; fraud prevention; establishment or defence of legal claims.
- Consent
- Not consent-based; required to operate the service securely.
- Cross-border transfer
- Requests are processed in United States and data is stored in Ireland (EU), so clinical data submitted to VetIOS crosses between those jurisdictions. Content sent to external AI model providers is processed on their infrastructure, whose location VetIOS has not verified.
Billing recordbilling_record+
Subscription, invoice, and payment status records. Card data is handled by the payment processor, not VetIOS.
- Controller
- VetIOS, which decides the purposes and means.
- Processor
- VetIOS, with the sub-processors listed in the privacy policy.
- Storage
- Data at rest: Supabase (Postgres, Auth, Storage) in AWS Europe (Ireland), eu-west-1 (observed 2026-09-15). Payment details are held by Stripe.
- Retention
- Kept for 7 years for tax and accounting obligations (pending counsel review).
- Training use
- Never.
- Secondary use
- Shared validation: never. Research: never. Federation: never. Population intelligence: never.
- Erasure
- Not deleted: Tax and accounting record-keeping obligations (pending counsel review). On request, the identity link is removed, the payload is minimized, the legal basis is recorded, and processing is limited to: tax; accounting; establishment or defence of legal claims.
- Consent
- Contract.
- Cross-border transfer
- Requests are processed in United States and data is stored in Ireland (EU), so clinical data submitted to VetIOS crosses between those jurisdictions. Content sent to external AI model providers is processed on their infrastructure, whose location VetIOS has not verified. Payment processing is handled by Stripe on its infrastructure.
Direct support interactionsupport_interaction+
Emails and messages sent directly to VetIOS support.
- Controller
- VetIOS, which decides the purposes and means.
- Processor
- VetIOS, with the sub-processors listed in the privacy policy.
- Storage
- The support mailbox.
- Retention
- Kept until a deletion request is executed. There is no automated retention or purge job.
- Training use
- Never.
- Secondary use
- Shared validation: never. Research: never. Federation: never. Population intelligence: never.
- Erasure
- Hard-deleted on request.
- Consent
- Initiated by the sender.
- Cross-border transfer
- Stays with VetIOS.
Website analyticswebsite_analytics+
VetIOS runs no website analytics or tracking scripts today. If introduced, VetIOS is the controller.
- Controller
- VetIOS, which decides the purposes and means.
- Processor
- VetIOS, with the sub-processors listed in the privacy policy.
- Storage
- Not collected.
- Retention
- Not collected.
- Training use
- Never.
- Secondary use
- Shared validation: never. Research: never. Federation: never. Population intelligence: never.
- Erasure
- Hard-deleted on request.
- Consent
- Would require consent where the law requires it.
- Cross-border transfer
- Stays with VetIOS.
Direct PetPass consumer accountpetpass_consumer_account+
An owner account created directly with PetPass, including notification preferences.
- Controller
- VetIOS, which decides the purposes and means. Counsel to confirm: direct-to-owner PetPass processing may make VetIOS a controller beyond account data.
- Processor
- VetIOS, with the sub-processors listed in the privacy policy.
- Storage
- Data at rest: Supabase (Postgres, Auth, Storage) in AWS Europe (Ireland), eu-west-1 (observed 2026-09-15). Supabase Auth and PetPass tables.
- Retention
- Kept until a deletion request is executed. There is no automated retention or purge job.
- Training use
- Never.
- Secondary use
- Shared validation: never. Research: never. Federation: never. Population intelligence: never.
- Erasure
- Hard-deleted on request.
- Consent
- Account terms; notification channels require owner opt-in.
- Cross-border transfer
- Requests are processed in United States and data is stored in Ireland (EU), so clinical data submitted to VetIOS crosses between those jurisdictions. Content sent to external AI model providers is processed on their infrastructure, whose location VetIOS has not verified.
Raw clinical caseraw_clinical_case+
Signalment, presenting signs, history, exam findings, lab values, and images a clinic submits.
- Controller
- The clinic (tenant) that submitted the data.
- Processor
- VetIOS, processing only on the clinic's instructions.
- Storage
- Data at rest: Supabase (Postgres, Auth, Storage) in AWS Europe (Ireland), eu-west-1 (observed 2026-09-15).
- Retention
- Kept until a deletion request is executed. There is no automated retention or purge job.
- Training use
- Not used to train model weights. No pipeline reads tenant databases into training data.
- Secondary use
- Shared validation: de-identified derivations only, with deidentified_training consent. Research: de-identified derivations only, with deidentified_training consent. Federation: de-identified derivations only, with network_learning consent. Population intelligence: aggregates only, with population_signal consent.
- Erasure
- Hard-deleted on request.
- Consent
- Clinic authorization to submit the case. VetIOS rejects imports that carry direct patient or owner identifiers.
- Cross-border transfer
- Requests are processed in United States and data is stored in Ireland (EU), so clinical data submitted to VetIOS crosses between those jurisdictions. Content sent to external AI model providers is processed on their infrastructure, whose location VetIOS has not verified. Images and free text sent to AI vision or assistant features are processed by an external model provider.
Patient identifierspatient_identifiers+
Patient names, microchip numbers, and similar direct identifiers.
- Controller
- The clinic (tenant) that submitted the data.
- Processor
- VetIOS, processing only on the clinic's instructions.
- Storage
- Data at rest: Supabase (Postgres, Auth, Storage) in AWS Europe (Ireland), eu-west-1 (observed 2026-09-15).
- Retention
- Kept until a deletion request is executed. There is no automated retention or purge job.
- Training use
- Never.
- Secondary use
- Shared validation: never. Research: never. Federation: never. Population intelligence: never.
- Erasure
- Hard-deleted on request.
- Consent
- Clinic authorization.
- Cross-border transfer
- Requests are processed in United States and data is stored in Ireland (EU), so clinical data submitted to VetIOS crosses between those jurisdictions. Content sent to external AI model providers is processed on their infrastructure, whose location VetIOS has not verified. Not sent to external model providers by design; governance packets and CIRE snapshots exclude them.
Owner identifiers submitted by a clinicowner_identifiers+
Owner names and contact details held in a clinic's records.
- Controller
- The clinic (tenant) that submitted the data.
- Processor
- VetIOS, processing only on the clinic's instructions.
- Storage
- Data at rest: Supabase (Postgres, Auth, Storage) in AWS Europe (Ireland), eu-west-1 (observed 2026-09-15).
- Retention
- Kept until a deletion request is executed. There is no automated retention or purge job.
- Training use
- Never.
- Secondary use
- Shared validation: never. Research: never. Federation: never. Population intelligence: never.
- Erasure
- Hard-deleted on request.
- Consent
- Clinic authorization.
- Cross-border transfer
- Requests are processed in United States and data is stored in Ireland (EU), so clinical data submitted to VetIOS crosses between those jurisdictions. Content sent to external AI model providers is processed on their infrastructure, whose location VetIOS has not verified. Not sent to external model providers.
Inference eventinference_event+
The input signature, ranked differentials, CIRE block, and lineage recorded for each inference.
- Controller
- The clinic (tenant) that submitted the data.
- Processor
- VetIOS, processing only on the clinic's instructions.
- Storage
- Data at rest: Supabase (Postgres, Auth, Storage) in AWS Europe (Ireland), eu-west-1 (observed 2026-09-15).
- Retention
- Append-only; retained as the audit record of each output.
- Training use
- Not used to train model weights. No pipeline reads tenant databases into training data.
- Secondary use
- Shared validation: de-identified derivations only, with deidentified_training consent. Research: de-identified derivations only, with deidentified_training consent. Federation: de-identified derivations only, with network_learning consent. Population intelligence: aggregates only, with population_signal consent.
- Erasure
- Not deleted: Retained as the audit record of a clinical decision-support output that was published or gated (pending counsel review of the exact legal basis). On request, the identity link is removed, the payload is minimized, the legal basis is recorded, and processing is limited to: audit of published decisions; patient-safety investigation; establishment or defence of legal claims.
- Consent
- Clinic authorization.
- Cross-border transfer
- Requests are processed in United States and data is stored in Ireland (EU), so clinical data submitted to VetIOS crosses between those jurisdictions. Content sent to external AI model providers is processed on their infrastructure, whose location VetIOS has not verified. The structured differential engine makes no external model call. Image inputs are sent to an external model provider.
Outcome eventoutcome_event+
A confirmed diagnosis or outcome attached to a prior inference, with its evidence type.
- Controller
- The clinic (tenant) that submitted the data.
- Processor
- VetIOS, processing only on the clinic's instructions.
- Storage
- Data at rest: Supabase (Postgres, Auth, Storage) in AWS Europe (Ireland), eu-west-1 (observed 2026-09-15).
- Retention
- Append-only; retained as the audit record of calibration and reliability statements.
- Training use
- Not used to train model weights. No pipeline reads tenant databases into training data.
- Secondary use
- Shared validation: de-identified derivations only, with deidentified_training consent. Research: de-identified derivations only, with deidentified_training consent. Federation: de-identified derivations only, with network_learning consent. Population intelligence: aggregates only, with population_signal consent.
- Erasure
- Not deleted: Retained as the audit record of a clinical decision-support output that was published or gated (pending counsel review of the exact legal basis). On request, the identity link is removed, the payload is minimized, the legal basis is recorded, and processing is limited to: audit of published decisions; patient-safety investigation; establishment or defence of legal claims.
- Consent
- Per-outcome learning_consent flags plus tenant-level consent scopes.
- Cross-border transfer
- Requests are processed in United States and data is stored in Ireland (EU), so clinical data submitted to VetIOS crosses between those jurisdictions. Content sent to external AI model providers is processed on their infrastructure, whose location VetIOS has not verified.
Derived calibration statisticderived_calibration_statistic+
Per-tenant calibration buckets: outcome counts, Brier score, and calibration error per label, species, and model version.
- Controller
- The clinic (tenant) that submitted the data.
- Processor
- VetIOS, processing only on the clinic's instructions.
- Storage
- Data at rest: Supabase (Postgres, Auth, Storage) in AWS Europe (Ireland), eu-west-1 (observed 2026-09-15).
- Retention
- Append-only; retained for audit of every reliability statement made from it.
- Training use
- Used for tenant-local calibration of displayed confidence and for CIRE reliability_state. It does not change model weights.
- Secondary use
- Shared validation: aggregates only, with deidentified_training consent. Research: aggregates only, with deidentified_training consent. Federation: aggregates only, with network_learning consent. Population intelligence: never.
- Erasure
- On request, the link to the tenant or person is removed and the anonymized record is kept.
- Consent
- Covered by the clinic's use of outcome confirmation.
- Cross-border transfer
- Requests are processed in United States and data is stored in Ireland (EU), so clinical data submitted to VetIOS crosses between those jurisdictions. Content sent to external AI model providers is processed on their infrastructure, whose location VetIOS has not verified.
External model requestexternal_model_request+
Content sent to a third-party AI model provider: images for vision analysis and text for the assistant.
- Controller
- The clinic (tenant) that submitted the data.
- Processor
- VetIOS, processing only on the clinic's instructions.
- Storage
- Transmitted to the provider for the request; the response is stored with the inference.
- Retention
- At the provider, under that provider's API data terms. VetIOS stores the response like any inference.
- Training use
- VetIOS does not use these requests to train models. Provider-side use is governed by the provider's API terms.
- Secondary use
- Shared validation: never. Research: never. Federation: never. Population intelligence: never.
- Erasure
- Hard-deleted on request.
- Consent
- Clinic use of the vision or assistant feature.
- Cross-border transfer
- Requests go to the provider's infrastructure (Anthropic; an OpenAI-compatible provider), whose location VetIOS has not verified. VetIOS cannot delete copies held by the provider.
Audit and governance logaudit_log+
Append-only records of governance gates, reliability packets, calibration snapshots, and review queues about clinic-submitted data.
- Controller
- The clinic (tenant) that submitted the data.
- Processor
- VetIOS, processing only on the clinic's instructions.
- Storage
- Data at rest: Supabase (Postgres, Auth, Storage) in AWS Europe (Ireland), eu-west-1 (observed 2026-09-15).
- Retention
- Append-only by database trigger; retained so every published decision stays auditable.
- Training use
- Never.
- Secondary use
- Shared validation: never. Research: never. Federation: never. Population intelligence: never.
- Erasure
- Not deleted: Retained as the audit record of a clinical decision-support output that was published or gated (pending counsel review of the exact legal basis). On request, the identity link is removed, the payload is minimized, the legal basis is recorded, and processing is limited to: audit of published decisions; patient-safety investigation; establishment or defence of legal claims.
- Consent
- Not consent-based; required for audit.
- Cross-border transfer
- Requests are processed in United States and data is stored in Ireland (EU), so clinical data submitted to VetIOS crosses between those jurisdictions. Content sent to external AI model providers is processed on their infrastructure, whose location VetIOS has not verified.
Federated updatefederated_update+
A masked, de-identified contribution a consenting tenant publishes to a federation round.
- Controller
- VetIOS, which decides the purposes and means. VetIOS coordinates the aggregate; each contribution is gated on the tenant's network_learning consent.
- Processor
- VetIOS, with the sub-processors listed in the privacy policy.
- Storage
- Data at rest: Supabase (Postgres, Auth, Storage) in AWS Europe (Ireland), eu-west-1 (observed 2026-09-15).
- Retention
- Kept until a deletion request is executed. There is no automated retention or purge job.
- Training use
- Aggregated into a network candidate artifact. The production engine is not retrained from it.
- Secondary use
- Shared validation: never. Research: never. Federation: this class is that use's output; every contribution required network_learning consent. Population intelligence: never.
- Erasure
- On request, the link to the tenant or person is removed and the anonymized record is kept.
- Consent
- Tenant network_learning consent and coordinator enrollment.
- Cross-border transfer
- Requests are processed in United States and data is stored in Ireland (EU), so clinical data submitted to VetIOS crosses between those jurisdictions. Content sent to external AI model providers is processed on their infrastructure, whose location VetIOS has not verified.
Aggregate epidemiology signalaggregate_epidemiology_signal+
Population-level counts and advisories with no clinic, patient, owner, or inference identifiers.
- Controller
- VetIOS, which decides the purposes and means. VetIOS decides how aggregates are computed and published; contributions are gated on population_signal consent.
- Processor
- VetIOS, with the sub-processors listed in the privacy policy.
- Storage
- Data at rest: Supabase (Postgres, Auth, Storage) in AWS Europe (Ireland), eu-west-1 (observed 2026-09-15).
- Retention
- Kept until a deletion request is executed. There is no automated retention or purge job.
- Training use
- No.
- Secondary use
- Shared validation: never. Research: never. Federation: never. Population intelligence: this class is that use's output; every contribution required population_signal consent.
- Erasure
- On request, the link to the tenant or person is removed and the anonymized record is kept.
- Consent
- Tenant population_signal consent for every contribution.
- Cross-border transfer
- Requests are processed in United States and data is stored in Ireland (EU), so clinical data submitted to VetIOS crosses between those jurisdictions. Content sent to external AI model providers is processed on their infrastructure, whose location VetIOS has not verified. Published aggregates are public once at least three clinics contribute.
Research exportresearch_export+
A de-identified dataset file prepared for research or shared validation.
- Controller
- VetIOS, which decides the purposes and means. VetIOS decides the export; each contributing record is gated on deidentified_training consent.
- Processor
- VetIOS, with the sub-processors listed in the privacy policy.
- Storage
- Files outside the production database, handled by the platform team.
- Retention
- Per export; no automated expiry.
- Training use
- Offline research models may be trained on curated export files. They are not the production clinical engine.
- Secondary use
- Shared validation: de-identified derivations only, with deidentified_training consent. Research: this class is that use's output; every contribution required deidentified_training consent. Federation: never. Population intelligence: never.
- Erasure
- Not deleted: De-identified copies already provided to research recipients cannot be recalled (pending counsel review). On request, the identity link is removed, the payload is minimized, the legal basis is recorded, and processing is limited to: reproducibility of completed research.
- Consent
- The contributing tenant's deidentified_training consent and provenance tracking.
- Cross-border transfer
- Depends on the research recipient; disclosed per export.
- No automated retention or purge schedule exists for any data class.
- Erasure is executed by the platform team through the erasure ledger; there is no self-service erasure.
- Controller and processor positions, retention periods, and legal bases are pending counsel review.
- Where external AI model providers process requests has not been verified.
vetios-data-governance-2026-09-26b
Limitations
- CIRE signals are structural and policy states; they are not clinical accuracy.
- Calibration is tenant-local. It does not retrain or update model weights.
- A network with fewer than two authorized participating clinics learns nothing across tenants.
- Partner access is provisioned manually after onboarding review.
- Operational status is inferred from recorded partner calls; with no calls there is no evidence either way.
- The published artifact is synthetic. It proves the verification mechanism, not clinical performance.
- No edge node runs clinical inference offline in production today unless counted below.
- The production clinical engine is a deterministic, versioned rule system; it has no trained weights to publish a card for unless listed.
- No automated retention or purge schedule exists for any data class.
- Erasure is executed by the platform team through the erasure ledger; there is no self-service erasure.
- Controller and processor positions, retention periods, and legal bases are pending counsel review.
- Where external AI model providers process requests has not been verified.
- VetIOS provides clinical decision support. It is not a regulated medical device and does not replace a licensed veterinarian.