HIPAA-compliant infrastructure
Platform architecture designed for protected health information. Business Associate Agreements available on request.
Security
Your data, your work product, your clients. Protected at every layer.
Platform architecture designed for protected health information. Business Associate Agreements available on request.
At rest and in transit. TLS 1.3 on every connection. Keys managed through a dedicated KMS.
Audit in progress. Attestation targeted for release following the current observation window.
We do not train on customer files. Your firm's work product stays your firm's.
Full CSV export. API read access. Enterprise customers can pipe directly into their data warehouse.
Granular permissions per user. Audit logging on every sensitive action. Session controls and SSO for Enterprise.
Audit Logging
Document views, exports, e-signatures, permission changes, and integration key rotations are logged with actor, timestamp, and target. Tamper-evident storage. Seven-year retention by default.
Stream the log to your SIEM on Enterprise.
BAA templates, security overview, SOC 2 progress summary. Available on request.
Request compliance packet