Governance you can audit, not a badge wall.
Every claim on this page maps to an artifact we can produce under NDA: certification letters, DR test records, model documentation, and agent-action audit trails.
Independently verified.
Certification letters and current audit reports available under NDA via our security contact.
Where your data sits, and who can reach it.
Every engagement starts with a data-flow map and a signed BAA. Access follows least privilege, and the answers below are the same ones we put in writing.
Residency and hosting
Client environments run in US regions on AWS or Azure. Production data stays in the client tenant unless a hosted model is contracted.
Encryption
TLS 1.2 or higher in transit, AES-256 at rest, with customer-managed keys supported where the platform allows.
Access control
Named-consultant access, MFA enforced, quarterly entitlement reviews, and revocation inside one business day of roll-off.
PHI minimization
De-identified or synthetic data for development and testing. Production PHI access is scoped to the task and logged.
Subprocessors
A current subprocessor list is maintained and shared under NDA. Material changes are communicated before they take effect.
Retention and return
Engagement artifacts are returned or destroyed on a documented schedule at contract close, with attestation provided.
Available on request, under NDA.
Security reviews move faster when the artifacts arrive with the first email. Your security team can request the full package before a contract exists.
Assurance reports
Current audit reports and bridge letters, plus the latest third-party penetration test summary.
Disaster Recovery records
Published DR exercise logs from our live Epic and MEDITECH hosting environments.
AIGaaS Model Cards
Sample model validation packages, CHAI assurance alignment, and continuous drift monitoring specs.