Validation audits
Zenlo Labs publishes model documentation in the CHAI Applied Model Card format and independent validation summaries for transparency. These materials describe a research clinical decision support tool — not an FDA-cleared medical device.
15 clinical patterns. 8 benchmarked across 5 AI models on 4,018 NHANES adults (F1 up to 0.963). Per-pattern NHANES audits published for 2 (Insulin Resistance, Metabolic Syndrome); the rest are structural CHAI cards, validation in progress.
Explore audits
Pattern model cards (15)
CHAI Applied Model Card summaries for each pattern in the Zenlo Labs engine. Full cards with validation tables live on the Labs product; this index mirrors the public audit catalog.
15 clinical patterns. 8 benchmarked across 5 AI models on 4,018 NHANES adults (F1 up to 0.963). Per-pattern NHANES audits published for 2 (Insulin Resistance, Metabolic Syndrome); the rest are structural CHAI cards, validation in progress.
Full CHAI cards open on labs.zenlo.app/audits. Marketing copy on /labs references 102 biomarkers in static panels; registry count on the biomarker sheets page is live from the database.
Reference library
Live reference sheets for all 102 biomarkers Zenlo Labs evaluates. Ranges and interpretation text are read from the registry database; citation provenance is under review. Research clinical decision support tool — not FDA-cleared.
Per-sheet detail pages remain on the reference library. Static marketing copy on /labs cites 102 biomarkers; the live page shows the registry row count, refreshed hourly. Categories and rows here are a representative sample.
Security & compliance
Methodology and results — Zenlo Labs. Structured self-assessment performed by the Zenlo team against recognized public security standards (not a certified third-party audit).
Why we publish this
Zenlo Labs is a physician-only clinical decision support (CDS) platform that processes laboratory data that may include protected health information (PHI). We trade FDA clearance for radical transparency — we publish validation audits (model cards, NHANES harness) and our security posture. This page is that security self-assessment.
The three standards we assess against
There is no single security standard that covers application code, cloud infrastructure, and regulatory compliance together. We self-assess against three recognized frameworks, each addressing a different layer.
The Application Security Verification Standard defines roughly 350 requirements across 17 chapters for secure application design and implementation. No official certification exists; verification is by self-assessment and penetration testing. We target Level 1, and Level 2 where feasible.
Supabase is SOC 2 Type 2 certified at the platform level. The customer is responsible for Row Level Security (RLS), SSL enforcement, Point-in-Time Recovery (PITR), network restrictions, MFA, service-role key handling, Security Advisor review, and — for PHI — a Supabase Business Associate Agreement (BAA), which requires a Team Plan.
Administrative, Physical, and Technical safeguards for electronic protected health information (ePHI). A 2025 OCR Notice of Proposed Rulemaking (NPRM) proposes stronger requirements; the current rule remains in effect. We assess against the current rule and note the proposed delta where relevant.
Compliance instruments
Factual status of agreements and controls — gaps are documented openly, not hidden.
Assessment areas & schedule
The assessment is performed in five areas. Each is dated when performed and its findings published here. The first cycle (areas 1–4) was self-assessed on 2026-05-22; remediation and re-test (area 5) is the next phase.
RLS enabled on all 15 tables; PHI isolated per-doctor; no permissive policies on PHI tables; 1 SECURITY DEFINER function with locked search_path. Findings: dead duplicate RLS policies — Medium; redundant grants on 5 deny-all tables — Low; mutable search_path on 2 functions — Low.
0 Critical, 5 High, 6 Medium. No hardcoded secrets, no auth backdoor, input validation solid, service-role server-only. Findings: Next.js 14.2.35 CVEs — High; incomplete middleware auth envelope — High; action-plan routes rely on RLS only — Medium; engineering errors surfaced to client/DB — Medium; no CSP/X-Frame headers — Medium; npm audit debt — Medium.
Postgres 17.6, SSL on, extensions clean, deployment protection on, HSTS present, /api/seed inert, no secrets in client bundle. Findings: MFA off — High; SSL enforcement toggle off — Medium; no network restrictions — Medium; no PITR — Medium; public bucket listing — Medium; leaked-password protection off — Low. Plan=Pro (Supabase BAA needs Team).
Mapped to Administrative/Physical/Technical safeguards. Access Control + Integrity Met. Audit Controls Partial. Authentication Partial (MFA off). Transmission Partial. BAA: Anthropic signed + ZDR active; Supabase BAA not in place. Posture: HIPAA-aligned, NOT HIPAA-compliant.
Scheduled — 19 prioritized remediation items identified; fixes and re-test to follow.
Findings summary (2026-05-22)
The first self-assessment cycle was performed on 2026-05-22 across four areas. No Critical findings were identified. The posture is early-stage and HIPAA-aligned, not yet HIPAA-compliant; appropriate for a pre-revenue stage operating on synthetic demonstration data (no real patient PHI in the system yet).
These items are tracked for remediation. This page will be updated with re-test results and dates as fixes land.
What this report does NOT claim