trust center · live posture

Built for healthcare-grade trust.

We move medical-billing data for a living. This page is the live posture of what's in place today, what's on the roadmap, and what isn't in scope yet. For the deep legal language, see /security.

AWS BAA signed HIPAA posture per-tenant isolationSOC 2 Type II in progress
live today

What runs in production. Right now.

live

AWS BAA signed

Business Associate Agreement with Amazon Web Services in force. Production workloads on HIPAA-eligible services only.

live

AES-256-GCM field-level encryption

PHI fields encrypted at application layer with per-tenant keys, on top of AWS-managed at-rest encryption.

live

MFA + sudo-mode

MFA required for all staff and customer admin roles. Destructive ops require re-authentication via sudo-mode.

live

Per-tenant data isolation

Enforced in every database read path. 53 routes audited under PR #47 with 0 cross-tenant leaks.

live

Audit log · 6yr retention

Every PHI access signed with caller, tenant, route, status, payload hash. 6+ year retention. Tamper-evident.

live

Rate limiting + CSP/HSTS

Per-bucket rate limits with X-RateLimit-* headers. Strict Content Security Policy. HSTS preload on every external endpoint.

live

PHI-redacted logging

Structured logs run through a PHI redactor before they leave the host. No patient identifiers in stdout, stderr, or app logs.

in progress · honest about it

On the roadmap. Not yet certified.

We don't claim certifications we haven't earned. Below is what we're actively working toward, and what we've decided to defer. If something here is a blocker for your security review, ask — we'll tell you the real timeline, not a sales one.

SOC 2 Type II

audit window open

Big-4-adjacent auditor engaged. Type II report expected H2 2026. Not claimed as complete.

HITRUST CSF

not started

Will pursue only if customer demand justifies the cost. Honest stance: most of our customers don't ask for it.

FedRAMP

not started

Out of scope for the commercial healthcare segment we serve today. Reconsider when we work with federal payers.

BYOK enterprise

H2 2026

Customer-managed keys via AWS KMS for enterprise tier. In-scope for the latter half of 2026 alongside SOC 2 Type II.

sub-processors

Every vendor we use. And how we treat their seat at the table.

Sub-processors with PHI access carry a Business Associate Agreement. Sub-processors that process operational data (non-PHI) carry a Data Processing Agreement. Anything else doesn't get our customers' data.

Sub-processorRegionPurposeAgreement
Amazon Web Servicesus-east-1 / us-west-2Compute, storage, KMS, IAMBAA
MongoDB AtlasUnited States (PHI tier)Primary application databaseBAA
VercelEdge · United StatesWeb hosting + edge runtimeDPA
TwilioUnited StatesVoice + SMS + telephonyBAA + DPA
ElevenLabsUnited StatesVoice synthesis for Echo agentsDPA
AnthropicUnited StatesClaude API for classification and draftingDPA
Microsoft GraphUnited StatesOutlook, Teams, OneDrive (Flux + Lisa)BAA + DPA
Google WorkspaceUnited StatesGmail, Calendar, Drive (Flux + Lisa)BAA + DPA
StripeUnited StatesSubscription billing + invoicingDPA
DocuSealSelf-hosted · AWS us-east-1BAA + contract e-signatureBAA
ResendUnited StatesTransactional email (non-PHI only)DPA
compliance posture

Where we sit. Per framework.

HIPAA

Yes

Full Privacy + Security Rule posture. AWS BAA signed. Customer BAA on Bonterms template available day one. PHI handling documented in /security.

CCPA

Yes

California consumer rights honored: access, deletion, opt-out of sale (we don't sell). Privacy notice + DSAR workflow live.

GDPR

Limited

We operate US-only today. We will not ship EU data residency or DPA-grade EU posture until we have a real European customer. Honest scope.

Texas HB 300

Yes

Texas-specific PHI handling overlay on top of HIPAA. Relevant for our Texas-based customers (counseling networks).

California CMIA

Yes

Confidentiality of Medical Information Act handled alongside HIPAA + CCPA for California practices on the platform.

long-form legal posture

For the deep dives, see /security.

The legal posture page goes deeper on infrastructure, application security, sub-processor commitments, incident response, breach notification, and customer obligations. If you're running a vendor risk review, start there.

questions for the security team?

Ask. We'll answer.

Send your security questionnaire, your DPA, your BAA. We'll respond with the same honest framing as this page. No marketing in the loop.