Trust

The rules we build to.

Castellan software handles health information about people on their worst day, for the clinicians whose registration stands behind every entry. These are design commitments, not marketing — the rules are older than any single feature, and features that break them don't ship.

1 · Offline first, because availability is a safety property

Anything a clinician needs to read works with no connectivity at all. Anything they write is accepted immediately and delivered when the network allows. A retry from an aircraft is the normal case, planned for from the first line of design — not an error to apologise for.

2 · Records append. They never silently change.

New information supersedes old; nothing is wiped. When two versions of the truth collide — as they genuinely do when two devices work the same job offline — the record keeps both, attributed and timestamped, and shows which one stands. An audit reads what happened, including the corrections.

3 · Two clocks, always

When something happened and when the system learned of it are different facts, and pretending otherwise is how records lie politely. Every entry carries both — the time attested by the clinician and the time recorded by the server, neither one overwriting the other.

4 · Nothing machine-made enters the record unconfirmed

AI transcription, device feeds, calculated scores — all of it is a suggestion until a person accepts it. The record keeps both facts: what the machine offered, and what the clinician decided. Decision support supports; it never decides.

5 · A machine can never countersign

Every signature in a Castellan evidence chain is a person. Integrations and services are their own class of identity, with their own narrow permissions — they can deliver data, but they can never witness a controlled drug, sign a check, or stand in a chain of custody. There is no configuration that changes this.

6 · Patient data lives apart

The equipment register holds no patient data — by architecture, not by policy. A service can run QuarterMaster with nothing patient-shaped in its database at all, and prove it. Where the clinical record and the register meet, the join carries the minimum the seam needs and nothing more.

7 · One service, one database

Castellan is not a shared pool with your rows in it. Every service runs on its own dedicated database — a bespoke tenancy built for one customer, holding one organisation's records and nobody else's. It can be stood up, audited and handed over on its own, because it is its own.

Privacy

We build against New Zealand's Privacy Act 2020 and the Health Information Privacy Code 2020 from the first schema, not as an afterthought before a sale. Data minimisation is a design habit: fields exist because a clinical or legal purpose needs them, feedback travels without telemetry weighing it down, and de-identification claims are treated with the suspicion they deserve. Beyond New Zealand, the posture is the same: wherever a service runs Castellan, its own country's health-privacy law is the floor we build from.

Questions about your information: privacy@castellan.nz.

Security & responsible disclosure

If you've found a vulnerability in anything we run, thank you for telling us first. Email security@castellan.nz — a human reads it, fast.

Hold us to it.

The rules above are the pitch. If they match how you think the record should work, we should talk.