Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
SurfViewer is an enterprise medical imaging collaboration platform built on top of OHIF Viewer. It extends the open-source viewer with enterprise authentication, role-based and attribute-based access control (RBAC/ABAC), comprehensive audit logging, and secure collaboration capabilities. The platform supports virtually all DICOM imaging modalities supported by OHIF while providing the security, governance, and workflow features required for enterprise deployment.
SurfViewer's Holistic Image Sharing enables users to securely share not only a medical imaging study, but also the entire reading workspace. Users can resume a study session from any device, share static study sessions with colleagues, or collaborate in real time through dynamic study sessions while preserving annotations, measurements, layouts, and workflow state. Fine-grained access control and complete audit trails help organizations securely collaborate across departments and institutions.
Show the rest of the publisher’s description (1 more line)
SurfViewer is designed for research, education, software evaluation, and investigation purposes. It is not intended for clinical diagnosis or medical decision-making. The platform is deployed entirely within the customer's AWS account, allowing customers to maintain control of their data, identity management, security policies, and cloud resources.
Highlights
Highlighted by the publisher on AWS Marketplace.
Enterprise medical imaging collaboration built on OHIF Viewer with secure authentication, RBAC/ABAC authorization, and comprehensive audit logging.
Holistic Image Sharing securely shares studies, persistent reading sessions, or real-time collaborative workspaces while preserving annotations, measurements, layouts, and workflow state.
Deploys entirely in your AWS account using a serverless architecture, keeping your imaging data under your control while minimizing infrastructure management and cost.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Plans and pricing as listed
1 listed- Units
Refund terms
As stated by the publisher on AWS Marketplace.
the product is free, no refund
Sources
Publisher resources
1 linkLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

