Signet
The pipeline behind signed screening reports.
Signet is the clinical reporting pipeline that partners licence under their own brand. They own clinic and employer relationships; Lumepath does not sell to patients.
-
01 · Hold
Hold Four fail-closed gates keep incomplete, invalid, mismatched or critical work with a clinician. -
02 · Intake
Intake Signed receipt and opaque reference. Unmatched rows quarantined, not guessed. Manual fallback CSV only — never XLSX. -
03 · Compose
Compose AI-augmented smart reports from versioned clinic templates — sealed after a named clinician releases. -
04 · Deliver
Deliver Patient one-use links, k-anonymous employer views, clinic write-back when bound and licensed.
Perspective
Infrastructure behind signed reports — not a retail product.
Screening reports are assembled, not calculated. Results arrive in mixed formats. The pack is complete only after a named clinician releases it. Incomplete or critical work stays in Hold. Patients get a private copy; employers get an aggregate that refuses groups below k ≥ 10.
Lumepath keeps the pipeline correct: hold rules, signed lineage, byte-identical regeneration, and a privacy floor that cannot be lowered. The four stages answer what arrived, why it waited, what was sealed, and who received what.
Pipeline
Results in. Clinician release. Then delivery.
Each hop is receipted; the next cannot start on held work. Each stage owns a refusal the others cannot fake. Nothing reaches a patient before a named clinician releases it. Job cards above open each stage.
Refusals
What the pipeline refuses
Cross-cutting stops. Stage pages carry the full per-stage list.
- Guessing unmappable intake, or overwriting a changed payload under the same identifier
- Unattended release of held or critical work — protocol acknowledgement is not release
- Unsigned wording as signed; silent rewrite after release; second-language without clinic-signed content
- Patient access before release; employer views below k ≥ 10; unbound write-back; cross-portal session reuse
Integrity
Sealed inputs. Receipted side effects.
Released reports regenerate byte-identical from sealed inputs. Every intake, release and delivery is receipted. Privacy floor k ≥ 10 is absolute — raiseable by the tenant, never lowerable. Residency: Trust · Residency.
Boundaries
What Signet does not do
Not a medical device / SaMD / FDA / CE — not clinically validated or approved. AI-assisted interpretation, smart reports and referral prediction support clinician and programme workflow; a named doctor releases every patient-facing report. Critical values never take an automatic path.
- Not a medical device / SaMD — no FDA, CE, “clinically validated” or “clinically approved” claim
- Referral suggestions and AI-assisted interpretation surface for review. They do not replace named clinician release. Critical values never take an automatic path to the patient.
- Does not offer unconstrained diagnosis, triage or risk-score as a platform diagnosis engine — assist stays behind release and Hold (see Pipeline · Compose)
- Does not sell to patients; does not pitch laboratories or employers as direct Lumepath buyers
- Does not publish customer names, logos, testimonials or usage counts
- Does not claim named lab, CMS or IdP integrations without a proved endpoint
Deployments are cloud-agnostic (GCP, Microsoft Azure, AWS, Oracle); SaaS defaults to GCP. White-label is joint configuration on first licences, with self-service branding as product direction — detail on Partners.
Stage
Signet is live. A new generation is under active build.
What partners licence today is production software. What is under build is the next generation of the same line. We do not publish customer names, logos or usage counts.
Delivery partners: write to the partner team.