Medence runs on your approved commercial knowledge — battlecards, policies, clinical evidence. Here is exactly how we treat it, in plain English. If anything on this page raises a question, ask us and we’ll answer it the same way.
Everything you upload remains your property, isolated to your company, and used for exactly one thing: answering and coaching your own reps. We never train AI models on your data.
Every answer cites its source document, version, and approval status. Supersede a document and the old version stops answering immediately — governance is enforced before the AI ever sees a question.
Traffic is encrypted in transit (TLS 1.2+) and your content is encrypted at rest on Cloudflare’s network. Secrets live in a managed vault, never in code.
Role-based access separates reps, managers, and admins. Demo access is issued per person and individually revocable. Every AI interaction is logged for audit.
Run Medence on our metered AI, or on your own enterprise key — Azure or Anthropic — so inference happens under agreements your IT team already governs.
Medence is a commercial enablement platform. It holds sales knowledge — not patient data, not medical records. Nothing in the product touches PHI.
THE INTEGRATION ROADMAP, IN THE OPEN
We publish our security roadmap the same way we publish our pricing: plainly, with honest status labels. Here is where each piece stands.
Pilot deployments will onboard with your Microsoft work accounts. Your organization’s own MFA policy — Microsoft Authenticator included — applies automatically, because authentication happens in your tenant, not ours. Medence never stores passwords. The platform’s user model was built for this from day one.
Your admin will point Medence at one approved document library. We read it with Microsoft’s narrowest permission (read‑only, limited to the single site you choose — nothing else in your tenant), and every synced document still passes through approval governance before it can answer. Your content never leaves SharePoint’s control; Medence connects to your systems — it doesn’t replace them.
Certification is on our commercial roadmap and we’ll publish progress here. Until then, this page is our security posture — and pilot customers get a data processing agreement and direct answers to any security questionnaire.