Trust
What we can show you, and what we cannot yet.
Pathos Vigil is investigational, no Intuitive Pathos product is deployed, and the company holds no security or quality certification. This page sets out regulatory status, data commitments, website security, vulnerability disclosure and accessibility, including what is not yet in place.
Last reviewed .
Current status
Intuitive Pathos is an early-stage company. Every product is in development or at an earlier stage, and none is available for sale. Pathos Vigil is an investigational medical device. It has not been cleared or approved by the U.S. Food and Drug Administration or any other regulatory authority, and it is not available for sale or clinical use. No clinical study of it is running.
The company holds no security or quality certification. There is no SOC 2 report, no ISO 27001 or ISO 13485 certificate and no HITRUST certification, and no independent penetration test has been done.
| Area | Current state | Not in place |
|---|---|---|
| Regulatory | FDA pre-submission in preparation for Pathos Vigil. | Any clearance or approval. Any clinical validation. |
| Development process | Two engagements with TDO for Pathos Vigil, signed in August 2026, covering an ISO 13485 design and development procedure and regulatory support. A software lifecycle appropriate to the intended classification is planned and documented. | An established quality management system; one is being set up. |
| Certification | None. | SOC 2, ISO 27001, ISO 13485, HITRUST, an independent penetration test. |
| This website | No cookies, analytics or third-party scripts; a strict content security policy; automated checks on every proposed change. | An independent accessibility audit. |
| Fairness | A per-subject baseline designed to reduce bias by construction. | Per-group accuracy results. They have to be measured before anyone can claim them. |
Regulatory
Investigational, and not cleared.
Pathos Vigil is an investigational medical device. It has not been cleared or approved by the U.S. Food and Drug Administration or any other regulatory authority, and it is not available for sale or clinical use. It is being developed for acute and critical care. The intended use is to surface a change to a clinician, who remains the decision-maker; autonomous clinical action is outside the scope of the design. It is not a diagnosis and not a replacement for clinical assessment.
Clinical decision logic is kept in Pathos Vigil. The non-clinical products, including Intuitive‑Me, Pathos Home and Pathos Workplace, are general-wellness or non-clinical offerings, are designed with no dependency on that logic, and make no diagnostic or therapeutic claim.
We will not describe clinical performance we have not demonstrated. No sensitivity, specificity, lead time or outcome figure for any Intuitive Pathos product appears on this site. Pathos Vigil has never run on a patient, and no result has been clinically validated. The clinical overview lists what we will and will not claim.
Data
What the design keeps where it is.
- Identifiable physiology is not federated
- The platform is designed so that identifiable physiology and each person’s baseline never cross the federation boundary. The restriction is designed into the type system rather than a setting, so a deployment would have no option that turns it off.
- Consciousness scored against the patient’s own baseline
- Pathos Vigil is designed to score level of consciousness against the patient’s own earlier state rather than a population threshold. The design aims to reduce bias by construction; whether it does so for every group is a question for measured, per-group results, which do not exist yet.
- Health privacy law
- We do not describe any product as HIPAA compliant. No certification for HIPAA exists. Compliance depends on how a system is deployed and operated, and it binds both the institution and any vendor that handles protected health information on its behalf. No product is deployed. Any future study that involves patient data would run under institutional review board oversight and the agreements the participating institution requires.
- This website
- The site sets no cookies and runs no analytics, advertising or tracking scripts. Apart from the hosting provider’s standard server logs, the contact form is the only thing that collects information, and the privacy policy says who processes it and how long it is kept. Please do not send patient-identifiable or export-controlled information through the form or by email.
Security
How the website is protected, and how to report a problem.
No Intuitive Pathos product is deployed, so the controls below apply to this website only. They are stated specifically enough to check.
- Transport
- HTTPS only, with HTTP Strict Transport Security for one year, including subdomains.
- Content security policy
- Every page is served with a content security policy that allows scripts and styles only from this domain, and no inline script runs. Images come from this domain or are embedded in the page itself; text uses fonts already on your device. No other site can frame a page, and forms submit only to this domain.
- Third parties
- None in the page: no web fonts, analytics, embeds or tracking pixels. The site is served by Netlify, which also processes contact form submissions. Form submissions and emailed reports reach us through our email provider.
- Change control
- Every proposed change to the site runs automated checks for leaked secrets across the full history, content-security-policy errors, broken internal links and accessibility regressions, and an automated scan of page text for prohibited claims, such as patent-status and FDA-status wording.
Vulnerability disclosure policy
If you find a security problem in this website, email matthew.lashomb@intuitivepathos.com with a description, the steps to reproduce it and the impact you expect. The same contact is published in our security.txt. You can report anonymously, and we credit reporters who ask to be credited.
- Scope
- The website at intuitivepathos.com. The Netlify hosting platform itself is out of scope; report problems in it to Netlify. If you come across something else that appears to belong to Intuitive Pathos, report it, but do not test it.
- Please do not
- Degrade the site’s availability, run automated scanning at volume, attempt social engineering or physical access, or access, change or keep anyone else’s data. Stop and tell us as soon as you have shown the problem exists.
- What you can expect
- We aim to acknowledge a report within five business days, keep you informed while we fix it, and agree on a disclosure date with you. There is no bug bounty.
Policy effective , reviewed at least once a year.
Accessibility
Accessibility statement.
This site should work for everyone, including people who use a screen reader, a keyboard, magnification or high-contrast settings. Our target is WCAG 2.2 Level AA.
- Where it stands
- Every proposed change runs automated accessibility tests (the axe-core rules for WCAG 2.2 Levels A and AA) on every page, in the light and dark themes, at desktop and phone widths. Automated tests find only part of what a person would, and no manual audit with assistive technology has been done yet, so we do not claim conformance.
- How it is built
- Semantic HTML with landmarks and a skip link, visible keyboard focus, color contrast checked in both themes, motion reduced when your system asks for it, and every page usable with JavaScript turned off. There is no accessibility overlay.
- Compatibility
- The automated tests run in Chromium. The pages use standard HTML and CSS and are meant to work in current versions of the other major browsers and with common screen readers, which have not yet been tested.
- Known limits
- Links on the evidence page go to publishers’ sites, which we do not control. Logo files in the press kit are images; the company name appears in text beside each one.
- Tell us
- If something does not work for you, email matthew.lashomb@intuitivepathos.com or use the contact form. We aim to reply within five business days.
Statement prepared .
More detail
For reviewers who need more than a web page.
Hospital IT, security and compliance teams evaluating a possible study, and program offices evaluating a capability, can ask for detailed security and data-handling documentation through the contact page. It is shared only under a confidentiality agreement, after recipient screening and, where it applies, export-control review.