Encryption everywhere
TLS 1.3 in transit, AES-256 at rest, with per-tenant key separation.
Security & trust
Security you can verify and portability you can exercise — the two halves of the same promise. One protects the data; the other proves it was never being held.
01
TLS 1.3 in transit, AES-256 at rest, with per-tenant key separation.
Enforced at the data layer, not just in application code, and tested continuously.
Every request authorized on its own merits, inside the network as well as outside it.
Documented RTO and RPO targets, with restores tested on a schedule and the results published to customers.
02
Granular permissions, location scoping, and custom roles — not three fixed tiers.
SAML and OIDC sign-on, enforced multi-factor, automated provisioning and de-provisioning.
Emergency access is permitted, announced, time-boxed, and reviewed.
Heightened controls for behavioral health, substance-use, reproductive, and minor records.
03
Every access and change recorded with purpose-of-use, in a log the application cannot rewrite.
Produce a patient’s access history on request, without a support ticket.
Retention and legal-hold policies you set, per record class and per jurisdiction.
Model and version recorded with every AI-assisted output, and the same audit trail as everything else.
HIPAA and HITECH obligations, information-blocking requirements, 42 CFR Part 2 handling, state privacy law, a signed BAA, penetration test summaries, subprocessor list, and our current SOC 2 report status — available as one package under NDA.
Request the compliance packageWe will tell you which certifications are held today and which are in progress. A vendor that blurs that line will blur other ones.