Security
Healthcare-Grade Security for Accreditation Readiness
Your policies contain sensitive information. We treat security as seriously as you treat patient safety.
AES-256-GCM
Military-grade encryption
HIPAA Ready
BAA available
SOC 2 Type II
In progress (ETA Q3 2026)
TLS 1.3
All connections encrypted
Data Encryption
- AES-256-GCM encryption for all data at rest
- TLS 1.3 for all data in transit
- Encryption keys managed via secure key management service
- All database fields containing sensitive data are individually encrypted
HIPAA Compliance
- Business Associate Agreement (BAA) available for all qualifying plans
- PHI handling follows minimum necessary standard
- Complete audit logs for all data access and modifications
- Regular risk assessments and security training for all staff
Infrastructure Security
- Google Cloud Run with managed container orchestration
- Cloud SQL with automated backups and point-in-time recovery
- Private VPC networking with firewall rules
- DDoS protection via Google Cloud Armor
- Automatic security patching and updates
Access Controls
- Role-based access control (RBAC) with principle of least privilege
- JWT-based authentication with short-lived tokens
- Session management with automatic expiration
- Multi-factor authentication support
- IP allowlisting available for enterprise plans
Data Handling
- Your data is never used to train AI models
- Configurable data retention policies
- Right to deletion — request complete data removal at any time
- Data processing agreements available upon request
- Regular data integrity checks and validation
Monitoring & Incident Response
- 24/7 infrastructure monitoring and alerting
- Documented incident response procedures
- Breach notification within 72 hours per HIPAA requirements
- Regular penetration testing and vulnerability assessments
- Structured logging with anomaly detection
SOC 2 Type II Certification
We are actively working toward SOC 2 Type II certification, with an estimated completion of Q3 2026. Our security controls already align with SOC 2 trust service criteria for security, availability, and confidentiality.
In Progress
Have Security Questions?
Download our security whitepaper or request a BAA. Our team is ready to walk through our security posture in detail.