Security & trust

Encrypted. Access-controlled. Logged.

HIPAA compliant

attest is built around HIPAA from the data model up — every record encrypted, scoped to its owner, and recorded on access.

  • Encrypted end to end

    TLS in transit and encryption at rest, with server-managed keys.

  • Row-level access

    Every clinical row is bound to its owner — a session only ever reads its own patients.

  • Audit trail

    Access to protected health information is recorded in an append-only log.

  • Private by default

    Teaching and eval flows strip names, dates, and identifiers before reuse.

Compliance posture
EncryptionTLS in transit · AES-256 at rest
Active
Row-level securityPer-owner, enforced in the database
Active
Audit loggingAppend-only PHI access trail
Active
De-identificationDirect identifiers stripped before reuse
Default
Business Associate AgreementFor teams and institutions
Available

Subprocessors, infrastructure, and the BAA packet.