generated: '2026-08-17' method: searched source: >- https://support.inato.com/connections (and its per-connector pages), https://support.inato.com/data-security, https://support.inato.com/docs/crio-integration-reference.html, https://support.inato.com/docs/eclinpro-integration-reference.html scope_note: >- Inato publishes NO API of its own, so none of these standards can be asserted of an Inato-published contract. Every `role:` below says whether Inato conforms as a CONSUMER of someone else's standardized API or as a subject of a compliance regime. This distinction is the whole point of the file: a reader must not come away thinking Inato ships a FHIR server. standards: - id: fhir name: HL7 FHIR / FHIR Bulk Data Access conforms: true role: consumer version: not stated evidence: - >- "Our integration with your EHR is established via bulk FHIR APIs that are configured as read-only." — https://support.inato.com/connections - >- Epic connector: Inato is a registered Epic FHIR app; the site installs it from Epic's Vendor Services / fhir.epic.com Downloads page using Inato's published client ID. — https://support.inato.com/connections/epic - >- Practice Fusion connector: "If your site is not yet subscribed to FHIR APIs, you must enable them before proceeding." - ModMed connector distributes an Inato FHIR client ID for the site to install. note: >- Read-only, inbound. Inato reads patient records out of site EHRs over the vendors' FHIR APIs and is architecturally prevented from writing back. Inato exposes no FHIR endpoint, publishes no CapabilityStatement, and no FHIR resource profiles. - id: oauth2 name: OAuth 2.0 conforms: partial role: consumer evidence: - >- Bearer-token authorization on the CRIO downstream calls ("Authorization: Bearer "). - >- Client-ID-based app installation into Epic and ModMed, the standard FHIR SMART/OAuth app-registration pattern. note: >- Inato acts as an OAuth client against EHR and CTMS vendors. It operates no authorization server — /.well-known/oauth-authorization-server and /.well-known/openid-configuration are 404 on every Inato host (see ../well-known/inato-well-known.yml). - id: oidc name: OpenID Connect conforms: false role: none evidence: - '/.well-known/openid-configuration returns 404 on inato.com, www.inato.com, marketplace.inato.com and support.inato.com (probed 2026-08-17)' note: >- The marketplace login at https://marketplace.inato.com/login is an email-code flow, not a published OIDC provider. - id: rfc9457 name: RFC 9457 Problem Details for HTTP APIs conforms: false role: none evidence: - >- No Inato API exists. The one error convention Inato documents is eClinPro's, and it is the opposite of RFC 9457: HTTP 2xx carrying an in-body {"success": false, "error": "..."} envelope. - id: hipaa name: HIPAA (45 CFR Parts 160/164) conforms: true role: business-associate evidence: - '"HIPAA \"Preparatory to Research\" (45 CFR §164.512)" — https://support.inato.com/data-security' - Business Associate Agreement (BAA) available; a signed BAA is a prerequisite for every EHR connector. - Identifying fields are stripped at upload/sync before AI processing. - id: gdpr name: EU GDPR conforms: true role: processor evidence: - GDPR listed as a compliance badge on https://support.inato.com/data-security - >- "Inato processes the data on your behalf, under your instruction and authorization" — processor posture stated explicitly. - Regional data-residency commitments claimed for the GCP environment. - id: iso27001 name: ISO/IEC 27001 conforms: claimed role: subject evidence: - ISO 27001 listed as a compliance badge on https://support.inato.com/data-security note: >- Claimed on the security page. The certificate itself is not published — it is available on request from security@inato.com, and the Drata trust center that would carry it is behind a bot challenge (see ../security/inato-trust-center.yml). - id: soc2 name: SOC 2 conforms: unknown role: subject evidence: - >- Not claimed anywhere on https://support.inato.com/data-security. Inato runs a Drata trust center, and Drata is predominantly a SOC 2 / ISO 27001 compliance-automation platform, but the trust center contents could not be read (HTTP 403, Cloudflare challenge) so SOC 2 is recorded as unknown rather than inferred. - id: 21cfr11 name: 21 CFR Part 11 (FDA electronic records/signatures) conforms: unknown role: subject evidence: - Not claimed on any public Inato page reviewed on 2026-08-17. note: >- Notable gap for a clinical-research platform that writes subject status into site CTMS systems. Recorded as unknown, not as a failure — Part 11 applicability depends on whether Inato is treated as a source-data system. - id: idempotency name: Idempotent write semantics conforms: n/a role: none evidence: - >- No Inato API. The downstream CRIO/eClinPro writes are described as "upsert" operations keyed on vendor-side deduplication rules rather than on an idempotency key. - id: pagination name: Standard collection pagination conforms: n/a role: none evidence: - No Inato API. The downstream vendor collection endpoints document no paging. ai_governance: note: >- Not a formal standard, but Inato publishes an unusually specific set of AI governance commitments that a buyer diligence process would otherwise have to ask for. Recorded here because it is the substantive machine-relevant disclosure on the platform. source: https://support.inato.com/data-security claims: - 'Model: Google Gemini, running inside Inato''s own Google Cloud projects.' - 'No site or patient data is used to train AI models; Google does not use it to train foundation models.' - 'No patient data sent to any third-party US-based LLM provider.' - 'Human-in-the-loop is mandatory: "the AI flags potential matches ... your site team reviews each patient and makes every final call".' - 'Explainability: criterion-by-criterion summary of met / not met / unknown with the clinical evidence used, which the site team can challenge and override.' - 'Bias control: each patient is assessed against protocol criteria individually, never ranked against other patients.' - 'Non-patient signals (user feedback on AI accuracy) may be used to tune prompts and configuration.' robots_posture: source: https://www.inato.com/robots.txt status: 200 detail: >- inato.com explicitly ALLOWS every named AI crawler — GPTBot, ChatGPT-User, ClaudeBot, Claude-User, PerplexityBot, Perplexity-User, Google-Extended, Meta-ExternalAgent, CCBot — with no disallow rules. The marketing site is fully open to agents; there is simply nothing machine-readable behind it.