Compliance you can hand to legal

HIPAA-minded by default. BAA on Premium.

Clear boundaries around PHI, encryption in transit and at rest, auditable activity, and documents your finance and legal teams expect.

HIPAA-minded defaults

Least-privilege access, no PHI in analytics, and audit trails on critical actions.

BAA available (Premium)

Standard Business Associate Agreement. Request, countersign, and download copies from your account.

Premiumi
Data residency & retention

US-hosted by default. Retention set sensibly; deletion & export controls available on request.

Audit trail

Timestamped activity you can reference in finance reviews and compliance audits.

Controls snapshot

At a glance
Encryption in transit
TLS 1.2+
Encryption at rest
AES-256
Access model
Least-privilege, role-based
PHI in analytics
Never
Data location
United States (default)
Exports & deletion
By request or via account owner

Compliance FAQ

Need something specific?
We’re happy to loop in compliance or legal for your review.