Security Overview
SOC 2 Type II aligned controls, least-privilege access, MFA-required for all administrators, full audit logging on every PHI access.
HIPAA Compliance
HIPAA-compliant infrastructure, signed BAAs with all subprocessors, technical and administrative safeguards documented per 45 CFR ยง164.
Encryption Standards
AES-256 at rest, TLS 1.3 in transit. Database encryption keys are managed and rotated automatically. Backups are encrypted and geographically replicated.
Data Retention
PHI is retained only for the contracted period. 30-day offboarding grace period, then certified destruction with a downloadable destruction certificate.
Hosting
US-region cloud hosting on HIPAA-eligible infrastructure with 99.95% uptime SLA. Production data never leaves the US.
Subprocessors
Supabase (database & auth), Twilio (SMS), Resend (email), Cloudflare (CDN). All under signed BAAs where PHI is processed.
Business Associate Agreement
Self-serve BAA is available before any PHI is entered. Electronic signature with automatic countersignature and stored PDF.
Incident Response
24/7 monitoring. P1 incidents trigger customer notification within 1 hour and a written post-mortem within 5 business days.