Security
How we handle your data, stated plainly.
Health-care and financial data deserve specifics, not badges. Below is what the platform enforces - each item is a control that exists in the product, not an aspiration.
Access
- Deny-by-default authorization: every request is checked against a role and practice capability matrix; anything unlisted is refused
- Access is scoped per practice - naming another practice's data returns a refusal that is itself audited
- Password sign-ins require a second factor (authenticator app); Google sign-in carries Google's own second factor
- Disabling a user or revoking a grant takes effect on their next request, not their next sign-in
- An invitation names who is asking, what they will see and what they will not, and when it expires, before anyone enters a credential; links expire after seven days (how to check an invitation came from us)
Accountability
- An append-only audit trail records sign-ins, data access, permission changes and agreement executions - who, what, which practice, when
- Month-end close carries preparer/reviewer dual control; post-lock edits raise alerts and land in the trail
- AI output is labeled as drafted, cites its inputs, and waits for human approval
- Every connection to an accounting firm or an MSO carries a review date twelve months out, and the practice can end it at any time
PHI
- No PHI-bearing source can connect to a practice before a Business Associate Agreement is executed - the platform enforces this gate
- Analytics run on de-identified aggregates; patient-level views sit behind a separate, additionally-gated tier
- An accounting firm's view is de-identified: no patient names, dates of birth, dates of service, diagnosis codes, or any figure built from fewer than 11 patients
- An MSO sees a member practice's patient-level figures only after that practice records its BAA with the MSO; the practice signs its own agreements, and its accounting firm cannot sign one for it
- AI processing of practice data runs under Business Associate Agreements with our model vendors
- This marketing site holds no PHI, and its screenshots come only from a synthetic-data demonstration environment
Infrastructure
- Runs on Google Cloud; data encrypted in transit and at rest
- Containers are minimal, non-root, distroless images; secrets live in a managed secret store, never in code
- Durable stores are versioned; your data exports on request and connection removal purges pulled reports
We do not currently claim third-party certifications. When an audit (SOC 2 or equivalent) completes, its report will be referenced here - not before.