Skip to content

Compliance

Tested with: Compliance programme status as of 2026-09

ProgrammeStatus
HIPAA Security Rule controlsShip with secure hosting (Phase 3). BAA available on Team and Enterprise.
SOC 2 Type IWithin three months after the HIPAA launch
SOC 2 Type IIAfter a six-month observation window
External penetration testBefore the HIPAA launch and yearly after; summary available under NDA
HITRUST, ISO 27001On customer demand
Accessibility (WCAG 2.2 AA)See the accessibility statement; VPAT available
SafeguardRequirementMechanism
AdministrativeRisk analysis and managementAnnual risk assessment; per-change threat model for anything touching HIPAA cells
AdministrativeWorkforce security and trainingBackground checks; annual HIPAA training with attestation before staff get HIPAA roles; quarterly access reviews
AdministrativeInformation access managementStaff RBAC; production access to HIPAA cells only via break-glass with ticket, time-boxed, recorded
AdministrativeContingency planHourly backups + PITR, cross-region, Object Lock; quarterly DR exercise; published RTO/RPO
AdministrativeBusiness associate contractsOur BAA with you; BAAs with sub-processors (AWS); payment and email providers receive no PHI
PhysicalFacility, workstation, device controlsCloud provider SOC reports; MDM-managed staff devices; no PHI on workstations
TechnicalAccess controlUnique ids; emergency access = break-glass; portal sessions expire 12 h absolute / 30 min idle on HIPAA orgs; encryption at rest with per-org keys
TechnicalAudit controlsEvery control-plane, admin and break-glass action; six-year retention; hash chain + Object Lock export
TechnicalIntegrityBackup checksums, verified restores, Object Lock, signed images
TechnicalPerson or entity authenticationMFA required for all members of HIPAA orgs; WebAuthn for staff
TechnicalTransmission securityTLS 1.2+ at the gateway; internal mTLS; no plaintext ports
Breach notification60-day notificationIncident process with a HIPAA breach decision tree; customer contact registry; target 72 hours

Team and Enterprise customers can download the current SOC 2 report (when issued), the penetration test summary, the sub-processor list and a completed security questionnaire (CAIQ and SIG Lite) from Compliance → Documents. Evidence is collected weekly by automation (IAM listings, MFA status, policy reports, backup verification results) and feeds our compliance platform, so reports reflect the current state.