TRUST CENTER

Publish, rather than gate.

A security review should not require a discovery call. Everything a CISO or procurement officer needs to form a view is on this page, with documents available under NDA.

DOCUMENT REQUESTS
  • SOC 2 Type II reportNDA
  • Penetration test summaryNDA
  • Completed CAIQNDA
  • SIG Lite responsesNDA
  • Security overview PDFNDA

Requests are answered within two business days by the security team, not by a sales representative.

POSTURE

Controls, stated plainly

Security

  • AES-256 at rest, TLS 1.3 in transit
  • Customer-managed keys on Enterprise and Sovereign
  • Row-level security tenant isolation
  • Annual third-party penetration test, summary on request
  • Documented vulnerability disclosure policy
  • Break-glass access with mandatory reason and audit

Compliance

  • SOC 2 Type II report, available under NDA
  • HIPAA Security Rule control matrix
  • GDPR Article 30 records of processing
  • DPA, BAA and Standard Contractual Clauses
  • Audit trails suited to JCI, NABH and CARF review

Data residency

  • UAE North · KSA Central · EU West · Canada Central · India South
  • Region pinned per tenant, or per facility at rung 4
  • Topologies: SaaS multi-tenant, dedicated tenant, single-tenant private cloud, sovereign, air-gapped on-premise

Availability

  • 99.9% SLA on Enterprise, 99.95% on Sovereign
  • RTO 4 hours, RPO 15 minutes
  • Multi-region failover with quarterly failover testing
  • Public status page

Audit & retention

  • Every read and write to clinical data is logged
  • Logs retained 7 years by default, configurable
  • Export as CSV or JSON, or streamed to your SIEM
  • Access to audit reads is itself audited

Send us your security questionnaire.

We answer SIG and CAIQ from a maintained response library, usually within two business days.