Compliance
An honest compliance posture, not a certification badge.
We would rather tell you exactly what exists today than display a certification we don't hold. This page is deliberately specific.
What the platform implements
- Access control consistent with HIPAA's Security Rule expectations — role-based permissions, computed per request.
- Audit controls — a tamper-evident, hash-chained log of every write to the system.
- Transmission security — the platform is designed to run entirely over TLS.
- Multi-tenant data segregation — application-layer scoping with an optional database-level Row-Level Security backstop.
What remains deployment-specific
- A signed Business Associate Agreement (BAA) — this is between your organization and your hosting/infrastructure provider, not something software alone grants.
- Encryption at rest — configured at the database and storage layer you choose to deploy on.
- Formal certification (HIPAA compliance attestation, SOC 2, HITRUST) — not currently held. We will not claim otherwise.
- Your organization's own policies — workforce training, incident response procedures, and breach notification processes are organizational, not something a software platform can provide on your behalf.
Why we're specific about this
Healthcare buyers are used to vendors overstating compliance posture. We'd rather earn trust by being precise: here is what the platform demonstrably does, and here is what depends on how and where you deploy it. If your procurement process requires a specific certification we don't hold, tell us directly — we'll give you a straight answer about fit, not a workaround.
Have a compliance requirement to discuss?
Bring your specific requirements to a demo and we'll walk through exactly what's covered today.