KuraPath
know your health
Governance & Responsibility.
KuraPath is committed to the ethical, transparent, and safe deployment of AI in health education. This document outlines how we govern our AI systems and our responsibilities to users, healthcare providers, and the community.
AI Ethical Principles.
Our AI governance is aligned with Australia's AI Ethics Framework (Department of Industry, Science and Resources) and the OECD AI Principles. We assess our platform against the following principles:
Human-Centred Values
AI outputs are designed to support health education and empower informed decision-making. We do not provide medical diagnosis or replace the role of qualified healthcare professionals.
Privacy & Security
Personal data is separated from health values before AI processing. We comply with the Privacy Act 1988 (Cth) and Australian Privacy Principles. User data is never used to train third-party AI models. All data is protected with quantum-resistant AES-256-GCM encryption at rest and hybrid post-quantum key exchange (X25519Kyber768) in transit. Voice sessions use ephemeral tokens (2-minute expiry, single-use) and all transcripts are persisted for audit compliance.
Reliability & Safety
AI interpretations are anchored in peer-reviewed clinical literature using retrieval-augmented generation (RAG) and our Biosphere World Model. Every AI output passes through an industry-leading 5-layer safety pipeline: deterministic pattern scanning with simulation certainty guardrails, dual-model LLM consensus evaluation (two independent Gemini instances with an expanded 12-criterion weighted rubric, incorporating simulation humility and environmental claims), grounding verification against retrieved evidence and the causal evidence registry, FMECA-inspired severity classification, and full observability with every evaluation persisted for audit and drift detection.
Transparency & Explainability
All AI-generated content is clearly labelled. Our governance framework, privacy policy, and security practices are publicly documented. Users can understand how and why insights are generated.
Fairness & Non-Discrimination
We design our AI systems to serve all users equitably, regardless of background, ethnicity, gender, language, or socioeconomic status. We provide multilingual voice AI support in 74 languages and conduct systematic bias and fairness evaluation across demographic variants including gender, age, and ethnicity to ensure output consistency.
Accountability
KuraPath maintains clear lines of responsibility for AI system outcomes. We document our decision-making processes and provide channels for users to raise concerns or provide feedback.
The Governance Gap
Only 31% of health insurers have defined AI governance models. Most payers are adopting AI without the frameworks needed to manage risk, ensure compliance, or demonstrate accountability to regulators.
KuraPath provides governance-ready AI out of the box: a dual-judge safety system with independent model consensus, FMECA-inspired severity classification for clinical risk, hallucination detection with structured logging, and a comprehensive evaluation suite that runs automatically on every code change.
Source: a16z, "AI Eats the World" Spring 2026
1. Scope of This Framework
This Governance Framework applies to all AI-powered features within the KuraPath platform, including but not limited to:
- Health Interpreter: AI analysis of uploaded pathology and laboratory results;
- Voice AI Companion: Live conversational health education and real-time accessibility in 74 languages, with transcript persistence for audit compliance;
- Researcher: Evidence-grounded health research answers by text or voice, with the latest admin-curated research surfaced via the dashboard widget;
- Topic Guides: AI-generated health education content with voice-enabled follow-up conversations;
- Biosphere Intelligence: Environmental health risk assessments using real-time data, satellite-derived environmental metrics, live hospital performance maps powered by AIHW, and voice briefings;
- LiveLong: Longevity protocol engine with voice coaching integration;
- Journey Tracking: AI-generated action paths and health milestones;
- Librarian: AI-curated health resource recommendations with voice-powered knowledge conversations;
- Kura Guide: Persistent AI health companion that provides contextual health education, proactive tips, and connected conversations across text and voice. Conversation history is stored with secure cloud persistence for continuity.
2. Human Oversight
We maintain meaningful human oversight over our AI systems:
- No autonomous clinical decisions: KuraPath AI never makes clinical decisions, prescribes treatments, or provides diagnoses. All outputs are educational only;
- User-in-the-loop: Users always have the final say. AI outputs are presented as educational information to be discussed with healthcare professionals;
- Content review: AI-generated educational content is periodically reviewed for accuracy, relevance, and safety;
- Feedback mechanisms: Users can report concerns about AI outputs via our support page;
- Escalation paths: Issues flagged through feedback are reviewed and actioned, with system improvements implemented as necessary.
3. Data Sovereignty & AI Processing
We treat health data as a fiduciary asset, not a commodity. Our data governance principles include:
- Identity separation: Personally identifiable information is removed from health data before it reaches any AI model;
- No model training: Your health data is never used to train, fine-tune, or improve third-party AI models;
- Purpose limitation: AI processing is strictly limited to generating educational health insights for the specific user who uploaded the data;
- Data minimisation: We only send the minimum data required for AI processing;
- Retention controls: AI processing outputs are stored securely within your account. You can delete your data at any time.
For full details on how we handle your data, see our Privacy Policy.
4. AI Safety & Risk Mitigation
Given the sensitivity of health information, we implement specific safety measures:
- Medical disclaimer enforcement: Every AI-generated output includes a clear disclaimer stating it is not medical advice and should be discussed with a healthcare professional;
- Evidence anchoring: AI insights are grounded in peer-reviewed clinical literature using retrieval-augmented generation (RAG), reducing the risk of unsupported claims;
- Voice interaction boundaries: Conversational AI agents are rigidly instructed to decline diagnosing users, refuse emergency triage, and provide standard mental health or medical support numbers if crisis language is detected. Voice AI operates under the same non-diagnostic guardrails as text-based features, with additional spoken disclaimers;
- Voice session security: All voice sessions use short-lived ephemeral tokens (2-minute expiry, single-use) to prevent unauthorised access. Tokens are generated server-side and cannot be reused once expired;
- Transcript audit trail: All voice conversation transcripts are persisted to the database for SOC 2 audit compliance. This provides a verifiable record of all health education delivered through voice interactions;
- Hallucination monitoring: AI outputs are continuously monitored by an independent safety evaluator, with all flagged outputs logged with severity classification and routed to admin review workflows;
- Automated quality assurance: We maintain a comprehensive evaluation test suite covering normal, abnormal, edge-case, adversarial, and multilingual inputs. This suite runs automatically on every change to AI-related code;
- Emergency safeguards: If AI analysis detects values suggesting a medical emergency (e.g. critically abnormal pathology results), the output prominently directs the user to seek immediate medical attention;
- Scope boundaries: The AI is constrained to health education topics and will not engage in unrelated conversations or provide advice outside its defined scope.
5. Intelligent AI Architecture
KuraPath uses an intelligent, context-aware AI architecture that enables our AI to dynamically retrieve relevant information during a conversation, rather than relying on static, pre-loaded data. This results in more personalised and evidence-grounded responses.
Safety by design:
- Controlled autonomy: The AI can only access a curated, restricted set of data sources relevant to health education. Each AI feature is given only the minimum access it requires — following the principle of least privilege;
- Automatic safeguards: Built-in circuit breakers and resource limits prevent runaway processing. If the AI encounters an issue, it terminates gracefully rather than producing unreliable output;
- Data sanitization: All information retrieved during a conversation is sanitized before being processed by the AI — ensuring internal system details are never exposed in user-facing outputs;
- Comprehensive audit trail: Every AI interaction is logged for performance monitoring, safety compliance, and continuous improvement — without storing personally identifiable health data in logs;
- Voice AI integration: Our voice AI features use the same safety architecture. When the voice assistant retrieves information mid-conversation, you'll see a brief status indicator while it accesses your data securely.
6. Bias & Fairness
We recognise that AI systems can reflect and amplify existing biases in healthcare data. We are committed to:
- Using clinical reference ranges that account for demographic and biological variations where relevant;
- Avoiding assumptions about users based on demographic data;
- Conducting systematic bias evaluation across demographic variants including gender, age, and ethnicity, measuring output consistency using statistical parity thresholds;
- Seeking diverse perspectives in the design and review of health education content;
- Being transparent about the limitations of AI-generated insights, particularly where clinical evidence may be less representative of certain populations.
7. Regulatory Alignment
KuraPath's governance practices are informed by the following frameworks and regulations:
- Australia's AI Ethics Framework: Eight voluntary AI ethics principles published by the Department of Industry, Science and Resources;
- Privacy Act 1988 (Cth): Including the Australian Privacy Principles and the Notifiable Data Breaches scheme;
- Therapeutic Goods Administration (TGA): KuraPath is an educational platform and does not provide therapeutic goods or medical device functions. We monitor TGA guidance on software-based health products to ensure ongoing compliance;
- OECD AI Principles: International guidelines for trustworthy AI;
- Australian Consumer Law: Ensuring fair, transparent, and honest representation of our AI capabilities and limitations.
8. Satellite Data Governance
KuraPath integrates satellite-derived environmental data to power Biosphere environmental health features. This section documents the provenance, licensing, and governance of these data sources.
Data Provenance
- AlphaEarth Foundations (Google DeepMind) — satellite environmental embeddings providing land cover, vegetation, and environmental context;
- Dynamic World (Google/WRI) — near-real-time land use and land cover classification from Sentinel-2 imagery;
- Perch 2.0 (Google DeepMind) — on-device audio classification model for environmental noise health assessment.
Licence Compliance
- AlphaEarth Foundations: Creative Commons Attribution 4.0 International (CC-BY 4.0) — attribution provided in accordance with licence requirements;
- Perch 2.0: Apache License 2.0;
- Dynamic World: Open Data (Google/WRI Earth Engine programme).
Accuracy & Human-in-the-Loop
- Satellite-derived environmental estimates supplement but do not replace clinical or certified environmental assessments;
- Satellite data is one input among many in the Biosphere health risk model — it is not used as a standalone diagnostic or clinical decision input;
- All satellite-derived outputs are clearly labelled as educational estimates and are subject to the same 5-layer safety pipeline as all other AI outputs.
Third-Party AI Models
- Perch 2.0 runs entirely on-device via WebGPU/ONNX Runtime. No audio data is transmitted to external servers. The model is used solely for environmental noise health classification.
9. Continuous Improvement
AI governance is an evolving discipline. We are committed to:
- Regularly reviewing and updating this governance framework as AI regulations and best practices evolve;
- Monitoring developments in Australian and international AI regulation;
- Incorporating user feedback into governance improvements;
- Transparent communication about material changes to our AI systems or governance practices;
- Publishing updates to this framework with version tracking and revision dates;
- Applying scientific software quality principles from peer-reviewed research to ensure our AI outputs are verifiable, reproducible, and validated against structured schemas and physiological bounds.
Questions About Our Governance?
Contact us at support@kurapath.com