Trust center
Security and compliance posture.
A concise review surface for teams evaluating attest: safeguards, subprocessors, BAA support, and current readiness notes.
Overview
attest is built for clinician-facing workflows that may involve protected health information. Production PHI use requires the appropriate organizational agreement, including a Business Associate Agreement where applicable.
This page summarizes the controls and service providers used in production. For security questionnaires, contract review, or a full evidence packet, contact contact@attest.health.
Control posture
- Hosting
- Production application hosting on Google Cloud.
- BAA accepted
- Encryption
- TLS in transit and encryption at rest for persisted clinical data.
- Active
- Access control
- Owner-scoped records and protected clinical routes.
- Active
- Audit logging
- PHI-sensitive actions are recorded for review.
- Active
- Business Associate Agreement
- Available for teams and institutions processing PHI.
- Available
Subprocessors
Production services are limited to infrastructure, transactional email, DNS, billing, and support paths. Email and support workflows are not intended for PHI.
- Google Cloud
- Production hosting, database, and storage.
- BAA accepted
- AWS SES
- Transactional email only.
- BAA active
- Cloudflare
- DNS only.
- No PHI path
- Stripe
- Billing.
- No PHI
- Microsoft
- Contact mailbox.
- No PHI support by policy
Review materials
- Business Associate Agreement support for covered teams and institutions.
- Security questionnaire and control-summary review by request.
- Backup and restore posture tracked as part of launch readiness.
- Last updated June 5, 2026.
Requests
For a BAA, institutional security packet, privacy request, or vulnerability report, email contact@attest.health.