Security
Built for healthcare — secured for it too.
CareVP runs on HIPAA-eligible AWS infrastructure with tenant isolation enforced at every layer, encryption everywhere, and an immutable audit log of every meaningful action. We're proud of how we built this — here's the high level.
Foundations
How your data stays safe
Tenant isolation
Your data, only yours
Every tenant's data is invisible to every other tenant — enforced at the database, the application, and the storage layer. A single bug in any one of those layers can't leak data on its own, and an automated regression test verifies the invariant on every code push.
Encryption
Everywhere, by default
AES-256 at rest with AWS KMS keys and annual rotation. TLS 1.2+ in transit with HSTS preload. HTTPS-only on every customer-facing surface. End-to-end, no exceptions.
Data residency
US-only, always
All customer data lives in AWS US-West-2 with disaster-recovery backups replicated to US-East-1. We don't store data outside the United States. Period.
Audit log
Every action, recorded
Logins, settings changes, exports, admin actions — every meaningful event writes to an immutable, hash-chained log retained for seven years. Privileged actions require multi-factor authentication and are captured with full context.
Compliance + frameworks
Aligned to the standards healthcare operators are held to
HIPAA Privacy + Security Rule
We operate as a HIPAA Business Associate. Business Associate Agreements are available for customers handling PHI, with 72-hour breach notification per the HIPAA 2026 Security Rule update.
SOC 2 Type II
Evidence collection underway against the AICPA Trust Services Criteria. We're happy to share interim control mappings + auditor letters under NDA for customer review.
State privacy laws
Self-serve data-subject rights workflow for California (CCPA/CPRA), Colorado, Connecticut, Virginia, Utah, Texas, and Oregon. Every request honored within 30 days.
Sub-processors
A short list by design — AWS (HIPAA-eligible services only), Anthropic, Stripe, and Postmark. Listed in our DPA with 30-day notice before any addition.
AI privacy
Your data trains nothing
The AI sees only what your tenant has given it — never another customer's data, never the public web, never a fine-tuning corpus. Every output is sourced; every claim traces back to its underlying record.
No training on your data
Your conversations, your data, your queries — none of it is used to train, fine-tune, or improve an AI model. Not ours, not Anthropic's, not anyone's.
No cross-tenant aggregation
We don't pool customer data across tenants for benchmarks, features, or analytics. Your competitive intelligence stays inside your tenant.
No PHI to the model
Where PHI is processed, identifiers are hashed and replaced before any prompt reaches the AI. The model sees structure, not patients.
Our guardrails
What we deliberately don't do
Restraint is a feature. The shorter this list gets, the worse the product gets. Here's what we've drawn a line on:
- We don’t train or fine-tune AI models on customer data — ever.
- We don’t aggregate data across tenants for product features, benchmarks, or analytics.
- We don’t make clinical-care recommendations. CareVP is a market-intelligence tool for operators, not a decision-support tool for clinicians.
- We don’t make billing-code (CPT, MDS) recommendations. AI outputs are filtered to block these patterns.
- We don’t store customer data outside the United States.