App security
medOS partner security relies on isolation, least privilege, immutable release proof, separate duties, current authorization, and visible fallback.
Activity logs
Release, certification, activation, mount, webhook, and integration events must be auditable without exposing PHI in public telemetry.
Documentation crawler policy
medOS has no application crawler equivalent to Stripebot.
Privacy
Every app handoff documents clinical purpose, data flow, scope, privacy, operations, retention, and support before hospital review.