Skip to main content

Security

Built for healthcare — secured for it too.

CareVP runs on HIPAA-eligible AWS infrastructure with tenant isolation enforced at every layer, encryption everywhere, and an immutable audit log of every meaningful action. We're proud of how we built this — here's the high level.

Foundations

How your data stays safe

Tenant isolation

Your data, only yours

Every tenant's data is invisible to every other tenant — enforced at the database, the application, and the storage layer. A single bug in any one of those layers can't leak data on its own, and an automated regression test verifies the invariant on every code push.

Encryption

Everywhere, by default

AES-256 at rest with AWS KMS keys and annual rotation. TLS 1.2+ in transit with HSTS preload. HTTPS-only on every customer-facing surface. End-to-end, no exceptions.

Data residency

US-only, always

All customer data lives in AWS US-West-2 with disaster-recovery backups replicated to US-East-1. We don't store data outside the United States. Period.

Audit log

Every action, recorded

Logins, settings changes, exports, admin actions — every meaningful event writes to an immutable, hash-chained log retained for seven years. Privileged actions require multi-factor authentication and are captured with full context.

Compliance + frameworks

Aligned to the standards healthcare operators are held to

Active

HIPAA Privacy + Security Rule

We operate as a HIPAA Business Associate. Business Associate Agreements are available for customers handling PHI, with 72-hour breach notification per the HIPAA 2026 Security Rule update.

In progress

SOC 2 Type II

Evidence collection underway against the AICPA Trust Services Criteria. We're happy to share interim control mappings + auditor letters under NDA for customer review.

Active

State privacy laws

Self-serve data-subject rights workflow for California (CCPA/CPRA), Colorado, Connecticut, Virginia, Utah, Texas, and Oregon. Every request honored within 30 days.

Disclosed

Sub-processors

A short list by design — AWS (HIPAA-eligible services only), Anthropic, Stripe, and Postmark. Listed in our DPA with 30-day notice before any addition.

AI privacy

Your data trains nothing

The AI sees only what your tenant has given it — never another customer's data, never the public web, never a fine-tuning corpus. Every output is sourced; every claim traces back to its underlying record.

01

No training on your data

Your conversations, your data, your queries — none of it is used to train, fine-tune, or improve an AI model. Not ours, not Anthropic's, not anyone's.

02

No cross-tenant aggregation

We don't pool customer data across tenants for benchmarks, features, or analytics. Your competitive intelligence stays inside your tenant.

03

No PHI to the model

Where PHI is processed, identifiers are hashed and replaced before any prompt reaches the AI. The model sees structure, not patients.

Our guardrails

What we deliberately don't do

Restraint is a feature. The shorter this list gets, the worse the product gets. Here's what we've drawn a line on:

  • We don’t train or fine-tune AI models on customer data — ever.
  • We don’t aggregate data across tenants for product features, benchmarks, or analytics.
  • We don’t make clinical-care recommendations. CareVP is a market-intelligence tool for operators, not a decision-support tool for clinicians.
  • We don’t make billing-code (CPT, MDS) recommendations. AI outputs are filtered to block these patterns.
  • We don’t store customer data outside the United States.