← iAvoxel
Compliance by design · Updated May 2026

Compliance & Regulatory Status

Sovereign hosting is not an afterthought — it is the first line of code. Below is the honest, current status of every compliance workstream across our intelligent clinical platforms. No marketing words, no overstatement.

Morocco Law 09-08 (CNDP)

Personal-data protection regime. CNDP declarations filed for IACardio and iAutisme under iAvoxel SARL (Karim El Mahi, founder). Authorization pending for health-data processing (Article 12) — application under review.

Declaration filed

Privacy policies published

Public privacy policies live across our domains. Designated DPO is currently the founder, while an external DPO migration is on the roadmap.

Published

Sovereign Moroccan hosting

All platform code and internal data stored on infrastructure located in Morocco. Zero foreign cloud dependency on patient data. Tier III/IV data-center alignment targeted with a Moroccan sovereign-cloud partner.

Hosted in Morocco

WCAG 2.1 AA accessibility

IACardio: ARIA live regions, focus trap on modals, skip links, keyboard navigation, 4 scripts (Latin, Arabic, Tifinagh). Screen-reader ready by design.

Implemented

FHIR R4 data model

AllergyIntolerance, Observation and Condition resources natively modeled. International coding standards used end-to-end (ICD diagnostic coding, LOINC lab panels).

Native

Intelligent clinical platforms

Our platforms ship intelligent clinical co-pilots — assistive components that compute, alert and suggest, while the physician remains the sole signing author of every diagnostic report. Step-up re-authentication, auto-save drafts and full audit trail are in production.

Production-ready

Malabo Convention

African Union data-protection convention. Country-local data-residency model designed for future sub-Saharan partners. Morocco: signatory (not ratified). Open to candidate African research and healthcare partners.

Model designed

DHIS2 integration

Integration-ready for Ministry-of-Health reporting pipelines. Bidirectional synchronization on the roadmap for the next development phase.

Integration-ready

ISO 13485 (QMS)

Quality Management System for medical devices. Gap analysis in progress. Certification timeline being scoped with regulatory partners.

Gap analysis

IEC 62304 Class B

Software lifecycle for medical-device software. Edition 2.0 (2026) integrates cybersecurity and AI/ML controls. Assessment under preparation.

Assessment

ISO 27001

Information-security management system. Pre-audit preparation under way; certification timeline to be confirmed with the chosen certification body.

Pre-audit

CE marking — Class IIa

Software-as-a-Medical-Device classification per IMDRF guidance. Multi-step regulatory roadmap. Filing target to be confirmed alongside the QMS and software-lifecycle certifications above.

Roadmap