Security & trust
Encrypted. Access-controlled. Logged.
HIPAA compliant
attest is built around HIPAA from the data model up — every record encrypted, scoped to its owner, and recorded on access.
- Encrypted end to end
TLS in transit and encryption at rest, with server-managed keys.
- Row-level access
Every clinical row is bound to its owner — a session only ever reads its own patients.
- Audit trail
Access to protected health information is recorded in an append-only log.
- Private by default
Teaching and eval flows strip names, dates, and identifiers before reuse.
Compliance posture
EncryptionTLS in transit · AES-256 at rest
ActiveRow-level securityPer-owner, enforced in the database
ActiveAudit loggingAppend-only PHI access trail
ActiveDe-identificationDirect identifiers stripped before reuse
DefaultBusiness Associate AgreementFor teams and institutions
AvailableSubprocessors, infrastructure, and the BAA packet.