Know where your scans go and who sees them.

Nitsor is where teams label CT and MRI scans and review AI suggestions. Here is what it stores, who can sign in and where it runs.

A real chest CT series as its files: 140 DICOM Part 10 files, 73.7 MB. Armato et al., "Data From LIDC-IDRI", TCIA, case LIDC-IDRI-0003, CC BY 3.0 (opens in a new tab), modified: windowed and stacked by Nitsor. Sources

Your data

What Nitsor stores, and where.

Your scans stay in your storage. The browser reads viewed slices from it through short-lived signed links, and model jobs work on temporary copies while they run.

In your storage
Your source scans, the masks people draw and the viewer copies Nitsor makes of registered scans, under a prefix you choose.
In Nitsor's records
File locations, checksums, scan geometry, labels, reviews and the history of the work. The records hold no image data.
Where hosted records live
On Team and Enterprise, Nitsor stores its records in the United States. Requests first reach the nearest edge location.
Storage keys
Bucket keys stay on the deployment. Nobody passes them through the dashboard, API or CLI, and no storage connection can delete.

Sign-in

Sign in the way your plan allows.

Everyone signs in to a named account on every plan. Enterprise connects your own identity provider.

Community
Through your own OIDC identity provider.
Team
Email and password, Google or Microsoft.
Enterprise
Single sign-on through your SAML or OIDC identity provider, with automated user provisioning by agreement.
Machines
Scripts and services use agent credentials with the scopes you choose and an expiry of at most 365 days. Nitsor stores only a fingerprint of each token.

Roles and access

Give each person only the access they need.

Workspace roles cover the account. Project access covers the work. Enterprise adds advanced access policies by agreement.

Workspace roles
Each person holds one of four roles: owner, admin, member or billing. Only owners and billing can change billing.
Project access
Inside a project, access is read, contribute, operate or admin. A member opens no project until someone grants access.
Review
A reviewer cannot review their own work unless a coordinator assigns it, and the record notes the exception.
Checks
Nitsor checks permission before every change, and clients connect over HTTPS.
The Access tab of a Nitsor project: A. Rivera is chosen from the people list and given Contribute from the four access levels, appears in the access table with that level, the four levels are explained (Read opens the project, Contribute works the queue, Operate edits taxonomy and instructions, Admin manages access), and M. Chen is granted the role reviewer in the stage roles table.
What each frame shows
  1. Choose a person and an access level
  2. A. Rivera is listed at Contribute
  3. Grant a role a stage can require
  4. M. Chen holds role reviewer

Audit history

Every change keeps a name.

The record shows who did what. Your quality process decides whether the work meets its requirements.

What the record keeps
Who drew each label, who reviewed it and which revision they saw. Events are only ever added, never edited.
Read-only access
Give auditors read-only access to labels, reviews and dataset versions, with no charge per person.
Exports
Labels, reviews and history stay readable on every plan: through the HTTP API on Team and Enterprise, and in your own deployment on Community. Enterprise adds administrative audit exports.

Deployment

Run Nitsor where your data rules require.

Teams with sensitive data can keep the whole stack on their own premises or in their private cloud.

Community
Free and self-hosted on your own infrastructure, on-premises or in your private cloud. Telemetry and billing are off.
Team
Hosted by Nitsor, with managed updates and backups of the hosted workspace data.
Enterprise
Hosted by Nitsor, or by agreement a private deployment on your premises or in your private cloud, set up with our help.

Assurance

Get the documents your review needs.

Enterprise customers receive security and procurement documentation. We agree deployment, support response times and data processing terms in the contract.

Certifications
Nitsor is working toward SOC 2 and HIPAA, including signing business associate agreements (BAAs).
Security contact
Write to [privacy contact email] with what you found and how to reproduce it.

Show us what you inspect.

Start with a public CT or MRI scan. See how a model suggestion becomes a reviewed label and a fixed training dataset.