Security & trust

Enterprise-grade security. Honest about where we are.

Here is exactly what protects your data today and what is in audit. We do not claim a certification before it is earned.

HIPAA compliant · BAA ready · AES-256 and TLS 1.3 · FHIR-native

HIPAA compliantBAA ready
SOC 2 Type IIIn progress
ISO 27001In progress

How your data is protected

Six pillars, built in from the start.

Encryption everywhere

AES-256-GCM at rest, TLS 1.3 in transit, with a dedicated key-management service.

Tenant isolation

Row-level security in PostgreSQL keeps every organization's data cleanly separated.

Access control

Fail-closed RBAC with SAML 2.0 and OIDC single sign-on for AD and Okta.

Audit & accountability

Every access is logged with user, timestamp, and reason. AI decisions carry explainability traces.

FHIR-native model

No proprietary schemas and no lock-in. Your data stays standards-based and portable.

Deployment flexibility

Cloud, private cloud, or on-premise, including air-gapped, for data-residency requirements.

Questions about security?

Talk to our team.

We are happy to walk your security and compliance teams through the details.