TRUST CENTER
Publish, rather than gate.
A security review should not require a discovery call. Everything a CISO or procurement officer needs to form a view is on this page, with documents available under NDA.
DOCUMENT REQUESTS
- SOC 2 Type II reportNDA
- Penetration test summaryNDA
- Completed CAIQNDA
- SIG Lite responsesNDA
- Security overview PDFNDA
Requests are answered within two business days by the security team, not by a sales representative.
POSTURE
Controls, stated plainly
Security
- AES-256 at rest, TLS 1.3 in transit
- Customer-managed keys on Enterprise and Sovereign
- Row-level security tenant isolation
- Annual third-party penetration test, summary on request
- Documented vulnerability disclosure policy
- Break-glass access with mandatory reason and audit
Compliance
- SOC 2 Type II report, available under NDA
- HIPAA Security Rule control matrix
- GDPR Article 30 records of processing
- DPA, BAA and Standard Contractual Clauses
- Audit trails suited to JCI, NABH and CARF review
Data residency
- UAE North · KSA Central · EU West · Canada Central · India South
- Region pinned per tenant, or per facility at rung 4
- Topologies: SaaS multi-tenant, dedicated tenant, single-tenant private cloud, sovereign, air-gapped on-premise
Availability
- 99.9% SLA on Enterprise, 99.95% on Sovereign
- RTO 4 hours, RPO 15 minutes
- Multi-region failover with quarterly failover testing
- Public status page
Audit & retention
- Every read and write to clinical data is logged
- Logs retained 7 years by default, configurable
- Export as CSV or JSON, or streamed to your SIEM
- Access to audit reads is itself audited
Send us your security questionnaire.
We answer SIG and CAIQ from a maintained response library, usually within two business days.
