xCures · Trust Center
Xcures Trust Center
Trust center
xCures maintains a public trust center covering its security and compliance posture.
HealthHealthcareMedical RecordsInteroperabilityFHIROncologyReal World DataClinical DataArtificial IntelligenceTEFCACarequalityPatient DataHITRUSTHIPAA
Trust center: https://xcures.com/trust/
Certifications & Compliance
Source
Trust Center
generated: '2026-09-04'
method: searched
source: https://xcures.com/trust/
url: https://xcures.com/trust/
http_status: 200
title: xCures trust & transparency
tagline: What we strive for, how we measure it, and where to verify it.
note: >-
Upgraded from the automated probe, which detected the keywords "SOC 2", "ISO 27001" and "HIPAA" on this
page and attributed all three to xCures. Reading the page shows that is wrong for two of them: SOC 2
Type 2 and ISO 27001:2022 are AWS's, which xCures inherits controls from. The certification xCures
itself holds is HITRUST e1, which the keyword probe missed entirely. Attribution is corrected below.
certifications_held_by_xcures:
- name: HITRUST e1 Certification
scope: xCures Clinical Clarity Engine
status: certified
year: 2025
upgrade_in_progress: HITRUST i1 Certification (2026)
quote: >-
"The xCures Clinical Clarity Engine is HITRUST e1 certified (in the process of being upgraded to
HITRUST i1 Certification)."
- name: HIPAA
scope: xCures and the Clinical Clarity Engine, operating as a business associate
status: compliant
validation: annual HIPAA evaluation plus assessments under the HITRUST certification program
certifications_inherited_from_aws:
attribution_warning: >-
NOT xCures certifications. The page states these are held by AWS, that xCures "is able to inherit
selected AWS HITRUST r2 controls to include as evidence in xCures's HITRUST certification program",
and that it "periodically reviews the AWS ISO 27001 certification and SOC 2 attestation report".
Attributing them to xCures overstates its posture.
certifications:
- name: HITRUST r2 Certification
holder: AWS
- name: ISO 27001:2022 Certification
holder: AWS
- name: SOC 2 Type 2 Attestation
holder: AWS
security_controls:
- control: Encryption
detail: In transit (TLS) and at rest
- control: Access Controls
detail: RBAC with least-privilege and minimum-necessary principles, MFA, and SSO
- control: Audit Logging
detail: Immutable logs via AWS + Datadog, SIEM monitoring
- control: Data Deletion
detail: In accordance with contractual requirements
- control: Provenance / audit trail
detail: Full CRUD audit logs maintained across all data access and modification events
data_governance_standards:
- standard: FHIR R4
detail: All extracted data mapped to FHIR R4 resources for downstream interoperability
- standard: OHDSI / OMOP
detail: Concepts normalized to OHDSI Standardized Vocabularies (SNOMED, LOINC, RxNorm)
- standard: mCODE
detail: Oncology-specific data elements aligned to the HL7 Minimal Common Oncology Data Elements profile
- standard: HIPAA
detail: HIPAA compliant with annual HIPAA evaluation and HITRUST certification program
ai_model_validation:
note: >-
Unusual for this catalog and worth recording: xCures publishes measured accuracy for the AI that
produces its API's output, with a stated method and a named limitation set. Most AI-in-the-loop
providers publish neither.
approaches:
- name: Schema-based extraction
detail: >-
NER + relation extraction over unstructured clinical documents into FHIR R4 and OHDSI-normalized
structured data, with linkage to source verbatim preserved per element.
- name: Checklist-based assertion
detail: >-
RAG over the full longitudinal record, returning structured outputs with source citations and
evidence-hierarchy rules to resolve conflicting documentation.
method: >-
Validated against clinically trained human reviewers; each field classified TP/TN/FP/FN with
third-reviewer arbitration on discrepancies; random 10% audit. Only explicitly stated, verifiable
extractions count as true positives — correct inferences not present verbatim are counted as errors.
deployment_threshold: accuracy and precision >= 95% before an extractor or checklist enters production
published_results:
- extractor: Medications
accuracy: 95.7%
precision: 97.5%
recall: 95.0%
f1: 96.3%
- extractor: Surgical Procedures
accuracy: 96.6%
precision: 97.7%
recall: 98.8%
f1: 98.2%
- extractor: Cancer Diagnosis
accuracy: 98.2%
precision: 98.7%
recall: 99.4%
f1: 99.0%
- extractor: Lines of Therapy
accuracy: 97.0%
precision: 95.4%
recall: 99.8%
f1: 97.6%
results_caveat: >-
xCures states these are a retrospective analysis of a defined historical dataset and do not guarantee
future performance.
source_citation: >-
Stuhlmiller TJ et al. "A Scalable Method for Validated Data Extraction from Electronic Health Records
with Large Language Models." Submitted for peer review, 2026. Full methods, supplemental tables and
raw counts available on request.
stated_limitations:
- >-
OCR quality — accuracy of extraction from scanned or faxed documents depends on document quality;
degraded scans may introduce errors or omissions.
- >-
Semantic search coverage gaps — checklists and schema LLMs rely on semantic search and use only the
top N semantically matched documents, so relevant information in lower-ranked documents can be
missed.
version_control: Extraction models are version-controlled and support rollback; A/B testing guides refinement
infrastructure:
hosting: AWS
monitoring: AWS + Datadog, SIEM
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/xcures-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.