# InFact > InFact (InFact UK Ltd, trading as "Infact — Solutions in public health") builds software for > communicable-disease control and public-health service delivery. Founded 2003 by Dr Chakib > Kara-Zaitri and Bob Hamilton. Silver Industry Partner of openEHR International (UK). Generated by API Evangelist on 2026-09-02 from public sources. This file is NOT published by InFact; it is an independent third-party profile. InFact serves no llms.txt of its own. ## What InFact makes - **HPZone** — the flagship suite for communicable-disease control, built on two decades of frontline work with the national health services of the United Kingdom and the Netherlands. Runs the full outbreak lifecycle from first signal to final analysis. - **HPCore** — case, contact and outbreak management, decision-support protocols, enquiry handling, contact tracing and monitoring, standardised risk assessment. - **EpiQ** — epidemiological questionnaires; deployable to non-clinical staff, data importable into existing systems. - **HPInsight** — dashboard and reporting over HPCore and EpiQ data for surveillance, analysis and modelling. - **Ampara** — the re-envisioned successor to SHDirect, covering the clinic patient journey: arrival, triage, consultation, diagnostics, prescribing, follow-up, capacity management and automated patient communication. ## API InFact operates a real, production API, and publishes nothing about it. - **Name**: HPZone API - **Style**: GraphQL, single POST endpoint - **Endpoint**: `https://api.hpzone.nl:8899/Edie` (Netherlands national deployment; note the non-standard TLS port 8899) - **Auth**: OAuth 2.0 client-credentials. `client_id` / `client_secret` are issued **by InFact** to the customer organisation. Tokens are minted by an external federation — `https://connect.govconext.nl/oidc/token` (GovConext / SURF), not by InFact. - **Scopes**: `standard` and `extended`, sent both in the OAuth flow **and** as a custom `scope:` request header on every call. - `standard` — the pseudonymised field set. - `extended` — adds the 92 fields carrying directly-identifying or special-category personal data (name, GP practice and address, telephone, ethnic origin, clinical conditions). - **Query roots** (6): `cases`, `contacts`, `situations`, `enquiries`, `actions`, `contexts` - **Fields**: 248 documented across those roots — Cases 113, Contacts 60, Situations 30, Enquiries 18, Actions 15, Contexts 12. - **Collection envelope**: `{ items { ... }, totalCount }` - **Pagination**: offset — `skip` / `take`, **maximum 500 rows per request**. - **Ordering**: `order: [ { Field: ASC } ]`. **Required for correct paging** — the server does not guarantee stable sort order, so a naive paging loop returns duplicate rows and silently omits others. The published client had to force an order clause in v1.2.0 for exactly this reason. - **Filtering**: `where: { Field: { eq | gte: value } }` - **Writes**: none documented. The public surface is read-only, so idempotency, dry-run and reversibility are all `na`. - **Errors**: GraphQL `errors[]` envelope. No RFC 9457 problem+json. - **Rate limits**: none published. The 500-row page cap is the only published request ceiling. ## Access There is no self-service signup, no sandbox, no free tier and no public pricing. HPZone is sold to national and regional public-health bodies under bilateral contract; API credentials are issued by InFact to the customer organisation. The API reference is customer-only — the CRAN client's own description states that "the API and its details are not publicly available", pointing holders of access to a Dutch GGD GHOR knowledge-network document library. ## Client libraries InFact publishes none, and operates no public GitHub organisation. One third-party client exists: - **HPZoneAPI** (R, CRAN, MIT) — v1.3.0, published 2026-04-09, ~278 downloads/month. https://cran.r-project.org/package=HPZoneAPI · https://github.com/ggdatascience/HPZoneAPI Written by the data-science team of GGD Noord- en Oost-Gelderland, a Dutch municipal health service, as a consumer of the API. It is the most complete public description of InFact's API that exists — and InFact did not write it. ## What InFact does not publish No OpenAPI, no GraphQL SDL (introspection is not reachable), no AsyncAPI, no developer portal, no API reference, no changelog, no pricing, no `/llms.txt`, no `/.well-known/` document of any kind, no A2A agent card, no MCP server, no CLI, no first-party SDK, no Postman collection, no public GitHub organisation, no security.txt or vulnerability-disclosure policy, and no trust center. A status-page host exists at `status.in-fact.com` but the vendor page is switched off. ## Reaching the company - Website: https://infact.solutions/ (behind a SiteGround JavaScript bot challenge — every path answers HTTP 202 with a challenge screen to non-browser clients) - Products: https://infact.solutions/hp-zone-products/ - Contact: https://infact.solutions/contact-us/ - Corporate domain `in-fact.com` redirects to infact.solutions. - openEHR partner listing: https://openehr.org/industry-partners/ ## Profile artifacts (this repository) - authentication/infact-authentication.yml — OAuth2 client-credentials + the `scope` header - scopes/infact-scopes.yml — standard vs extended, mapped field-by-field - data-model/infact-data-model.yml — 6 entities, 248 fields, inferred relationships - conventions/infact-conventions.yml — pagination, filtering, errors, reversibility (`na`) - conformance/infact-conformance.yml — GraphQL/OAuth2/OIDC yes; openEHR membership ≠ conformance - packages/infact-packages.yml — the one third-party client, with version and date - lifecycle/infact-lifecycle.yml — the disabled status page and the retired product-info host - rate-limits/infact-rate-limits.yml — an honest zero, plus the 500-row page cap - plans/infact-plans-pricing.yml — no published plans - well-known/infact-well-known.yml — a recorded absence across both hosts - mcp/infact-mcp.yml — no server exists; a derived candidate tool surface only - security/infact-domain-security.yml — TLS 1.3, no HSTS, no DNSSEC, no CAA, SPF+DMARC p=none