Overview

What has to be true before a scan-to-plan pilot can be trusted.

A concise operating surface for requirements, compliance boundaries, security controls, and deployment prerequisites.

Healthcare reviewPolicy before launchOperational guardrailsDeployment governance

Platform model

Compute and execution profile

Model development, training, and benchmark orchestration run on NVIDIA GPUs and Pasqal QCs (quantum computing systems), with workload routing selected by task profile, queue health, and validation requirements.

Public documentation focuses on operating expectations and compliance framing while protecting implementation safety and proprietary controls.

Program statement

Confidentiality-safe program positioning

The statement below is provided for legal and compliance context while preserving proprietary implementation confidentiality.

  • NEXQ and LuxLeaf AI are developing a research-stage, security-reviewed PACS-oriented web/mobile workflow concept for 3D segmentation research and professional collaboration.
  • The program scope may include imaging-review, segmentation-research, and professional-collaboration workflows; it is not represented as world-first, fully quantum-encrypted, FDA-authorized, clinically validated, or production-ready unless each claim is separately substantiated and approved.
  • This public documentation statement is intentionally high-level and does not disclose non-public architecture, cryptographic implementation specifics, model internals, or proprietary pipeline design.
  • All outputs remain review-support artifacts and require qualified professional review, institution-level governance, intended-use analysis, and legal/regulatory controls before any clinical or production use.

Compliance

Compliance and legal requirements

NEXQ documentation is structured for legal, security, and operations review before production onboarding.

Healthcare privacy baseline

HIPAA-aligned operations

Role-based access, minimum-necessary handling, audit trail visibility, and controlled release workflows are built into operational patterns.

Cross-region policy posture

GDPR-aligned controls

Data lifecycle handling supports access, correction, retention, and deletion request pathways with accountable policy checkpoints.

Human-in-the-loop requirement

Clinical and medical-use boundaries

Outputs are review-support artifacts and require qualified human review; clinical use requires intended-use classification and any required authorization.

Enterprise implementation gate

Contract and governance alignment

Production use requires contractual controls, security review, approved access scopes, and institution-specific legal acceptance.

Security controls

Security control baseline

Security controls combine identity governance, transport protection, audit readiness, controlled release boundaries, and the published trust, privacy, and data-collection policies below.

Identity and access boundaries

Role-scoped authentication, forced re-authentication pathways, and session lifecycle controls reduce unauthorized access risk.

Transport and envelope safeguards

Security posture requires TLS transport protections and encrypted data lanes for sensitive workflow operations.

Audit and traceability signals

Sign-in events, route access, and high-risk actions are designed to be observable for governance and forensic review.

Controlled release boundaries

Operational exports and disclosures are expected to pass policy checkpoints before release.

Published Policy

Trust and Security Policy

Full audited baseline for security governance, administrative safeguards, technical safeguards, SDLC controls, third-party assurance, and vulnerability disclosure.

Open Policy

Published Policy

Data Collection, Minimization, and Retention Policy

Full audited policy for collection limits, intake review, telemetry, mobile permissions, retention, deletion, vendor collection, and data inventory.

Open Policy

Published Policy

Incident Response and Breach Notification Policy

Operational incident triage and legally required notification posture for security, privacy, and regulated-data events.

Open Policy

Published Policy

Privacy Policy

Complete public privacy policy, including categories collected, purposes, cookies/SDKs, AI, health data, retention, security, and rights requests.

Open Policy

Deployment requirements

Production deployment controls

Organizations integrating NEXQ should complete these requirements before go-live.

  • TLS 1.3 where feasible; TLS 1.2 minimum only where risk-accepted with approved cipher suites, HSTS, certificate lifecycle management, and strict origin controls
  • Authenticated, role-scoped access with session timeout and forced re-authentication handling
  • Audit logging for sign-in, access changes, sensitive workflow actions, and export activity
  • Documented data retention windows and legal hold controls
  • Operational incident response process with defined escalation contacts
  • Documented HIPAA/GDPR policy ownership with institutional governance sign-off
  • Ongoing monitoring for uptime, latency, and security configuration drift

Governance

Clinical, legal, and disclosure governance

NEXQ provides role-aware systems and documented security controls. Organizations remain responsible for legal review, clinical governance, and policy adoption in their own jurisdiction.

  • Designate a compliance owner and incident commander before production release.
  • Define approved use boundaries for diagnostics, oncology, cardiovascular, and optimization workflows.
  • Establish retention and deletion controls per legal and contractual requirements.
  • Require human review for medical and operational decisions that affect patient care.
  • Publish client-facing disclaimers and obtain organization-level legal acceptance.

Policy lifecycle

Policy change management and publication controls

NEXQ policy and legal documentation updates are managed as controlled releases with verification, traceability, and confidentiality protections.

  • Policy revisions follow change-control gates with legal, security, and operations owner sign-off before release.
  • Major documentation or policy updates run through an eight-pass consistency and integration loop before publication.
  • Public-facing policy statements are confidentiality-safe and exclude non-public cryptographic, model, and infrastructure internals.
  • Material changes require updated effective dates, revision traceability, and linked references across privacy, documentation, and workspace notices.

IP and licensing

Intellectual property and licensing posture

NEXQ maintains a proprietary licensing posture for protected platform IP, while respecting the independent rights of partner and third-party organizations.

  • TumorQ, LiMiQ, HeartQ, and related source materials are proprietary to NEXQ and/or its licensors unless explicitly stated otherwise in writing.
  • Third-party logos, names, trademarks, service marks, and brand assets remain the property of their respective owners.
  • No implied license is granted by website access, documentation access, API access, or workspace access.
  • Any permitted use must remain bounded by executed agreements, applicable law, and policy-governed release controls.

Operations

Operational runbook and support boundaries

This page is a technical and policy overview and does not replace legal counsel, regulatory assessment, or licensed medical judgment.

Infrastructure profile

Model development and benchmark orchestration may use approved compute resources identified in internal architecture records. Third-party names do not imply endorsement or partnership unless separately authorized.

Runtime reliability

Production operations target controlled latency envelopes, graceful degradation, and guarded release checks before deployment.

Security reporting

Security or privacy concerns should be reported through official contact channels for triage and response coordination.

Documentation scope

Public documentation intentionally excludes proprietary implementation details while preserving legal and operational clarity.

Operating notes

The docs make the quiet safeguards visible.

Compliance, security, PACS-oriented exchange, and access controls are the behind-the-scenes work that makes a patient-first workflow credible.

Open contact path
01

A person first

The work begins before a scan appears on a screen.

02

Patient signal

Symptoms, imaging, history, constraints, and goals travel together.

03

Evidence review

Findings stay close to confidence, limitations, and source context.

04

Plan context

Diagnosis support and care-pathway discussion remain in the same frame.

05

Secure handoff

Providers, patients, and institutions keep the record moving safely.

Documentation keeps public claims bounded while preserving enough structure for legal, security, and implementation teams to evaluate fit.

Why NEXQ now

For healthcare buyers, trust is a product feature.

Documentation is part of the sale because hospitals need to see how the product would be governed: data boundaries, access roles, audit posture, PACS-oriented exchange, and human clinical review before production reliance.

Hospitals

Adopt intelligence without breaking EHR, PACS, compliance, or purchasing reality.

Clinicians

Spend less time hunting for context and more time judging the case.

Patients

Know what is happening, access their scans, and keep their providers aligned.