Trust center

Security and compliance posture.

A concise review surface for teams evaluating attest: safeguards, subprocessors, BAA support, and current readiness notes.

Overview

attest is built for clinician-facing workflows that may involve protected health information. Production PHI use requires the appropriate organizational agreement, including a Business Associate Agreement where applicable.

This page summarizes the controls and service providers used in production. For security questionnaires, contract review, or a full evidence packet, contact contact@attest.health.

Control posture

Hosting
Production application hosting on Google Cloud.
BAA accepted
Encryption
TLS in transit and encryption at rest for persisted clinical data.
Active
Access control
Owner-scoped records and protected clinical routes.
Active
Audit logging
PHI-sensitive actions are recorded for review.
Active
Business Associate Agreement
Available for teams and institutions processing PHI.
Available

Subprocessors

Production services are limited to infrastructure, transactional email, DNS, billing, and support paths. Email and support workflows are not intended for PHI.

Google Cloud
Production hosting, database, and storage.
BAA accepted
AWS SES
Transactional email only.
BAA active
Cloudflare
DNS only.
No PHI path
Stripe
Billing.
No PHI
Microsoft
Contact mailbox.
No PHI support by policy

Review materials

  • Business Associate Agreement support for covered teams and institutions.
  • Security questionnaire and control-summary review by request.
  • Backup and restore posture tracked as part of launch readiness.
  • Last updated June 5, 2026.

Requests

For a BAA, institutional security packet, privacy request, or vulnerability report, email contact@attest.health.