Not an HMSThe revenue layer above the one you already run — orchestration for hospitals, health aggregation for employers.See the difference →

Home · Trust

Security practices

  • Transport encryption on everything, with HSTS and no downgrade path.
  • Encryption at rest for the database and for backups.
  • Per-person accounts. No shared logins internally, for the same reason we do not allow them in the product.
  • Every access to a patient record is logged, including ours.
  • Dependencies are monitored for known vulnerabilities.
  • A content security policy that permits no inline script beyond a fixed set of hashes.
What we do not claim

We do not hold ISO 27001 or SOC 2 today. Saying so is more useful to you than a page implying otherwise. If a certification becomes a requirement for you, tell us — it affects our roadmap.

NADI · DOCUMENT
● Status current
● Plain language yes
● Contact stated
✓ published, dated, binding

We would rather you checked. All of it is written down.

How we are paid, what we will not build, and the reasons to be suspicious.