Clonify Labs logoclonify labs

Trust & Regulation

The system suggests, the clinician approves. The liability framework is clear from the start.

In medical software, trust is built on data security, regulatory compliance and writing down explicitly who holds decision authority. This page spells out all three.

System suggestedClinician approved

The clinician-approved automation philosophy

Automation in Clonify runs on deterministic geometry algorithms: the same input always produces the same output — predictable and verifiable behaviour. The system never diagnoses or decides treatment at any step; it measures, suggests and waits for the clinician's approval. This is not a limitation but a deliberate design choice: in medical software, predictability is exactly what regulators and physicians want.

Clinician's hand signing a digital approval on a tablet

Your data is hosted in Türkiye

Patient files and scan data are stored on secure infrastructure hosted in Türkiye; they are not transferred abroad.

KVKK-compliant data processing

Data is stored encrypted; access is limited to users authorized by your clinic. Processing follows the requirements of Turkish data protection law (KVKK).

Compliant with custom-made device regulation

Under custom-made medical device regulation, manufacturer responsibility stays with the clinic; Clonify strengthens the clinic's regulatory file by recording every design step.

The decision always stays with the clinician

Clinical judgements such as trimlines, regional shaping and the delivery decision cannot be delegated to software; critical steps do not advance without clinician approval.

Traceability is architecture, not a by-product

Every device's design history, measurements and approvals are archived automatically. When a medicolegal question arrives, your file is ready.

Quality roadmap

Work to align our quality management system with the ISO 13485 framework is ongoing; we will keep the status current on this page.

The lifecycle of your data

StagePractice
CollectionScan data is collected at the clinic with the patient's/guardian's informed consent.
StorageStored encrypted on servers in Türkiye; access is role-based and logged.
ProcessingMeasurement and design run inside the clinic's account; data is not used for module training without anonymization.
SharingReport sharing is controlled by the clinic; data is never sold to third parties.
DeletionPatient data is permanently deleted at the clinic's request; deletion is logged.

Liability is asked often; our answer is clear

The answer to “who is liable?” is set by regulation: for custom-made devices, manufacturer responsibility already sits with the clinic — as it did in the plaster era. Clonify does not change that responsibility; it strengthens the clinic's hand by recording every step. For an ill-fitting device, the answer to “what was done at which step?” now lives in the system, not in memory.

Let's answer your security and regulatory questions directly

If you want technical detail on KVKK, data hosting or our regulatory position, talk to our team.

Your data is hosted in Türkiye

A clinician approves every step

Compliant with custom-made device regulation

Trust & Regulation — Data Security and Clinician Approval | Clonify Labs