Security

Healthcare-Grade Security for Accreditation Readiness

Your policies contain sensitive information. We treat security as seriously as you treat patient safety.

AES-256-GCM

Military-grade encryption

HIPAA Ready

BAA available

SOC 2 Type II

In progress (ETA Q3 2026)

TLS 1.3

All connections encrypted

Data Encryption

  • AES-256-GCM encryption for all data at rest
  • TLS 1.3 for all data in transit
  • Encryption keys managed via secure key management service
  • All database fields containing sensitive data are individually encrypted

HIPAA Compliance

  • Business Associate Agreement (BAA) available for all qualifying plans
  • PHI handling follows minimum necessary standard
  • Complete audit logs for all data access and modifications
  • Regular risk assessments and security training for all staff

Infrastructure Security

  • Google Cloud Run with managed container orchestration
  • Cloud SQL with automated backups and point-in-time recovery
  • Private VPC networking with firewall rules
  • DDoS protection via Google Cloud Armor
  • Automatic security patching and updates

Access Controls

  • Role-based access control (RBAC) with principle of least privilege
  • JWT-based authentication with short-lived tokens
  • Session management with automatic expiration
  • Multi-factor authentication support
  • IP allowlisting available for enterprise plans

Data Handling

  • Your data is never used to train AI models
  • Configurable data retention policies
  • Right to deletion — request complete data removal at any time
  • Data processing agreements available upon request
  • Regular data integrity checks and validation

Monitoring & Incident Response

  • 24/7 infrastructure monitoring and alerting
  • Documented incident response procedures
  • Breach notification within 72 hours per HIPAA requirements
  • Regular penetration testing and vulnerability assessments
  • Structured logging with anomaly detection

SOC 2 Type II Certification

We are actively working toward SOC 2 Type II certification, with an estimated completion of Q3 2026. Our security controls already align with SOC 2 trust service criteria for security, availability, and confidentiality.

In Progress

Have Security Questions?

Download our security whitepaper or request a BAA. Our team is ready to walk through our security posture in detail.

AccredMock — AI-Powered Joint Commission Readiness