When you hand us your customers and your data, you're trusting us to protect them. We're built for that — certified, audited and compliant to the standards enterprise buyers require.
Cardholder and payment data is handled to the payment-card industry's security standard.
Attestation of Compliance on request.Our information-security management system is independently certified to the global standard.
Certificate on request.An independent auditor has verified our security controls operate effectively over time — not just at a point in time.
Report available under NDA.Protected health information is handled to US healthcare privacy and security requirements.
Key for CareHub and healthcare clients.Personal data is processed to EU privacy standards, with data-processing agreements available.
Key for EU/UK data.Beyond the certifications, security is built into how we operate: encryption in transit and at rest, role-based access controls, secure and monitored infrastructure, full audit trails, agent-level security policies, and business-continuity through multi-site redundancy. Human-in-the-loop controls and audit logging apply to our AI agents too.
We hold the documentation behind every standard above — certificates, our PCI Attestation of Compliance, and our SOC 2 Type II report — and provide them to your security and vendor-risk team under NDA during evaluation. We're glad to complete security questionnaires and join a review call.
HIPAA + SOC 2 Type II (CareHub).
PCI DSS + SOC 2 Type II.
GDPR + ISO 27001.
Bring us your questionnaire and your standards. We'll show you the documentation and how we deliver.