Skip to content
CircusScale

Security & trust

Your healthcare data is yours.

Security you can verify and portability you can exercise — the two halves of the same promise. One protects the data; the other proves it was never being held.

01

Protecting the data

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest, with per-tenant key separation.

Tenant isolation

Enforced at the data layer, not just in application code, and tested continuously.

Zero-trust access

Every request authorized on its own merits, inside the network as well as outside it.

Disaster recovery

Documented RTO and RPO targets, with restores tested on a schedule and the results published to customers.

02

Controlling who sees it

Roles you define

Granular permissions, location scoping, and custom roles — not three fixed tiers.

SSO, MFA, SCIM

SAML and OIDC sign-on, enforced multi-factor, automated provisioning and de-provisioning.

Break-glass with teeth

Emergency access is permitted, announced, time-boxed, and reviewed.

Sensitive-record handling

Heightened controls for behavioral health, substance-use, reproductive, and minor records.

03

Proving what happened

Immutable audit log

Every access and change recorded with purpose-of-use, in a log the application cannot rewrite.

Disclosure accounting

Produce a patient’s access history on request, without a support ticket.

Configurable retention

Retention and legal-hold policies you set, per record class and per jurisdiction.

AI governance

Model and version recorded with every AI-assisted output, and the same audit trail as everything else.

Portability is a feature, not a concession

  • Standard bulk export on every plan, self-service, at no charge.
  • Open formats and a documented data model — no proprietary dump nobody can read.
  • Continuous sync into your own warehouse if you would rather not wait for an export.
  • Contract language that says all of the above, so it survives a change of account manager.

The paperwork your compliance team will ask for

HIPAA and HITECH obligations, information-blocking requirements, 42 CFR Part 2 handling, state privacy law, a signed BAA, penetration test summaries, subprocessor list, and our current SOC 2 report status — available as one package under NDA.

Request the compliance package

We will tell you which certifications are held today and which are in progress. A vendor that blurs that line will blur other ones.