Health Canada Approved SaMD Class II
Clinical Digital Platform

Powering Precision Medicine with Clinical Live Patient Monitoring.

AppMed™ is a web-based platform that, when integrated into clinical workflows, consolidates real-time patient-recorded data into a comprehensive, easy-to-interpret clinical profile, supporting more informed decisions at every step of care. Regardless of your profile, whether you’re a patient, clinician, researcher, institution, or partner, AppMed™ is a platform built for you.

3

THERAPEUTIC AREAS

7+

CLINICAL PARTNERS

100%

CANADIAN

Patient Centricity in Practice

Three Integrated Solutions,
One Unified Platform

At the heart of our mission and vision is patient centricity. Driven by collaboration, compassion, and innovation, we are committed to enhancing health outcomes and improving patient experiences, not as a principle, but as a measurable clinical commitment embedded in every feature we build.

Optimizing ADHD Dosing Protocols
Model-informed precision dosing using Bayesian PK/PD algorithms, moving ADHD treatment from population averages to individual optimization.
Smart Clinical Alerts
Configurable notifications based on predefined thresholds that highlight clinically meaningful changes in real time to support continuous patient monitoring.
MME-Guided Tapering with PRO Surveillance
Individualised opioid dose-reduction plans built on real MME calculations, with continuous patient-reported outcomes tracking wearing-off effect and disengagement before they escalate.
Early Detection of Chronic Opioid Use
Longitudinal pain monitoring and adherence tracking algorithms, enabling clinicians to identify dependency risk signals before they become clinical crises.
Personalised HRT Management — Continuously Monitored
Move beyond snapshot clinic visits. AppMed™ supports the full HRT clinical cycle, from individualised dosing and longitudinal symptom tracking to early detection of therapeutic drift, giving clinicians a continuous, data-driven view of each patient's hormonal response.

Security & Compliance

Enterprise-Grade Infrastructure,
Built in Canada blue

Hosted on AWS Montréal, compliant with Law 25 and ISO/SOC standards — click each pillar to learn more about how we protect your data.

Canadian Hosting
Canadian
Hosting
Law 25 Compliant
Law 25
Compliant
Encryption
& Access
Certifications
Certifications
& Governance

Canadian Hosting — AWS Montréal

AWS Montréal Multi-AZ Redundancy Data Sovereignty

Québec-based infrastructure. Clinical-grade resilience. Full data sovereignty by design.

The AppMed™ Platform is deployed exclusively within the AWS Canada (Montréal) region, ensuring that all data remains within Canadian jurisdiction and under Québec data protection laws, unless otherwise explicitly agreed in writing.

Our infrastructure is designed to meet the expectations of healthcare organizations, research environments, and regulated digital health platforms.

  • Québec-Based Data Residency: All patient and system data are hosted and processed within the AWS Montréal region, ensuring full alignment with Québec Law 25 and Canadian data sovereignty requirements.
  • High Availability, Multi-Zone Architecture: The platform is deployed across multiple AWS availability zones, ensuring fault tolerance, high availability, and continuity of operations under infrastructure failure scenarios.
  • Enterprise-Grade Physical & Environmental Security: AWS data centers operate under strict physical security controls, including restricted access, continuous surveillance, and audited operational procedures.
  • Network Isolation & Defense-in-Depth: Segmented network architecture, firewalls, and controlled access layers protect system components and minimize attack surface.
  • End-to-End Encryption: Data is encrypted in transit and at rest using industry-standard protocols, ensuring secure communication across all platform components.
  • Continuous Monitoring & Threat Detection: Infrastructure is monitored in real time with logging, alerting, and anomaly detection to support proactive risk management.
  • Automated Backups & Disaster Recovery: Regular, automated backups combined with tested disaster recovery procedures ensure data integrity, recoverability, and operational resilience.

Infrastructure designed not just for uptime, but for clinical trust, regulatory alignment, and uninterrupted patient oversight.

Law 25 (Québec) & PIPEDA Compliance

Law 25 Compliant PIPEDA Compliant Annual Audit

Built for Québec. Aligned with Canada. Engineered for clinical-grade data governance.

AppMed™ operates the Platform in strict compliance with Québec’s Act respecting the protection of personal information in the private sector (Law 25) and Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA).

Our architecture, policies, and operational controls are designed to meet the expectations of healthcare institutions, research ethics boards, and regulated clinical environments.

  • Designated Privacy Governance: A formally appointed Privacy Officer oversees compliance, risk management, and regulatory alignment across all operations.
  • Québec-Based Data Residency: All patient data is securely hosted within Québec-based infrastructure (AWS), with no transfer outside jurisdiction, ensuring full alignment with provincial data sovereignty requirements.
  • Strict Data Minimization & Purpose Limitation: Personal information is collected and processed solely for defined clinical, operational, or research purposes as contractually agreed with the Healthcare Organization.
  • Role-Based Access & Institutional Control: Access to identifiable patient data is strictly limited to authorized clinical personnel within the Healthcare Organization. AppMed does not access or use patient data beyond its defined technical role.
  • Granular, Informed Consent Framework: Consent mechanisms are embedded within workflows, enabling transparent, traceable, and purpose-specific authorization aligned with Law 25 requirements.
  • End-to-End Security Safeguards: Encryption (in transit and at rest), access controls, audit logging, and continuous monitoring are implemented in accordance with industry standards (aligned with SOC 2, NIST, and ISO 27001 principles).
  • Auditability & Traceability: All platform interactions, data entries, and modifications are logged, enabling full audit trails for clinical, operational, and regulatory review.
  • Incident Response & Breach Management: Structured incident response protocols ensure rapid identification, containment, and notification in accordance with mandated timelines under Law 25.

Not just compliant, AppMed™ is built to operate within the highest standards of clinical data governance in Canada.

Encryption & Access Controls

TLS In-Transit Encrypted At Rest RBAC

End-to-end data protection. Controlled access. Built for clinical confidentiality.

AppMed™ implements a layered security model combining strong encryption, strict access governance, and full auditability to ensure the confidentiality, integrity, and controlled use of patient data across the Platform.

All safeguards are aligned with industry standards (SOC 2, NIST, ISO 27001 principles) and reflect AppMed’s contractual commitments regarding data protection, access limitation, and non-clinical role.

  • End-to-End Encryption (In Transit & At Rest): All data is encrypted using industry-standard protocols during transmission and storage, ensuring secure handling across all system components.
  • Secure Key Management: Cryptographic keys are managed using controlled, industry-aligned practices designed to prevent unauthorized access and ensure data integrity.
  • Strict Role-Based Access Control (RBAC): Access to data is governed by role-based permissions aligned with the Healthcare Organization’s structure, ensuring users can only access the information necessary for their function.
  • Least-Privilege Enforcement: Access rights are minimized by default and granted only as required, reducing exposure and limiting risk across all user levels.
  • Healthcare Organization-Controlled Access to Identifiable Data: Access to identifiable patient information is restricted exclusively to authorized personnel within the Healthcare Organization.
    AppMed does not access or use identifiable patient data beyond its defined technical and platform support role, as reflected in contractual agreements.
  • Authentication & Identity Controls: Unique user identities, secure authentication mechanisms, and controlled credential management ensure traceable and accountable system access.
  • Audit Logging & Traceability: All access events, data interactions, and system activities are logged, enabling full traceability for clinical oversight, compliance audits, and incident investigation

Not just encrypted, AppMed™ ensures that the right data is accessible only to the right people, at the right time, under full institutional control.

Certifications & Governance

SOC 1 & SOC 2 Type II ISO 27001 ISO 27018

Standards-aligned security. Controlled governance. Transparent accountability.

AppMed™ operates under a structured cybersecurity and governance framework aligned with internationally recognized standards, while leveraging AWS-certified infrastructure to ensure a secure and resilient hosting environment.

Security responsibilities are clearly defined across infrastructure and application layers, consistent with a shared responsibility model and AppMed’s contractual commitments.

  • AWS Certified Infrastructure (Hosting Layer): The AppMed™ Platform is hosted on AWS, which maintains globally recognized certifications including SOC 1, SOC 2 Type II, and ISO 27001/27018, ensuring secure and compliant infrastructure operations.
  • Application-Level Security Governance (AppMed Layer): AppMed governs the application layer through internal cybersecurity policies and operational controls covering access management, data protection, and platform integrity.
  • Alignment with Industry Security Frameworks: AppMed’s security practices are designed in alignment with recognized standards, including:
    • SOC 2 principles (security, availability, confidentiality)
    • ISO 27001 (Information Security Management)
    • ISO 27018 (Protection of personal data in cloud environments)
    • NIST Cybersecurity Framework
  • Vulnerability & Patch Management: Continuous monitoring, vulnerability assessment, and timely patching processes are implemented to maintain platform security and reduce exposure.
  • Structured Incident Response Program: Formal incident response procedures are in place, including escalation protocols, containment measures, and breach notification processes aligned with applicable regulatory requirements (including Law 25).
  • Personnel & Operational Security Controls: Internal policies govern personnel access, confidentiality obligations, and secure operational practices across the organization.

Not just certified infrastructure, AppMed™ delivers governed, accountable, and audit-ready security at the application level.

Ecosystem

Our Partners and Collaborators

AppMed™ combines dosage optimization, continuous clinical follow-up, and treatment adherence into a single Health Canada approved environment.

OUR PARTNERS



OUR COLLABORATORS

One Platform
Multiple Clinical Use Cases

AppMed™ supports healthcare providers, organizations, and research teams by transforming real-world patient data into actionable clinical insight, across the full care continuum.

Registre des calculs · Niveaux de risque visibles


Trois niveaux de risque — alignés sur les recommandations CMAJ​

Busse. CMAJ March 18, 2024 196 (10) E327-E340
Faible

MME total quotidien sous le seuil de risque modéré.

Modéré

≥ 50 MME/jour — révision et surveillance accrues.

Élevé

≥ 90 MME/jour — bannière d’avertissement affichée.

Voies orale, transdermique et parentérale prises en charge. Table de conversion modifiable par administrateur.

Pharmacologie non-linéaire — bannière de prudence dédiée plutôt qu’une conversion linéaire trompeuse.

Chaque calcul est tagué avec la version de la table de conversion en vigueur — interprétable même après mise à jour.

Une fois associé à un PSO actif, le calcul devient immuable — la valeur ancrant le sevrage ne peut plus être modifiée.


Quatre étapes pour calculer un MME

The result displays a total daily dose, a color-coded risk level, and, when the 90 MME/day threshold is exceeded, an inline clinical warning.

1- Sélectionner les opioïdes

Une ligne par molécule (orale, transdermique, parentérale).

2- Saisir dose et fréquence

Doses par jour et dose unitaire.

3- Vérifier le total

Niveau de risque chromatique et avertissement le cas échéant.

4- Sauvegarder

Tag horodaté + version de référence pour ancrage au PSO.