Trust & Security
ClarioScope is built for healthcare. This page lists every certification, control, and posture we publicly commit to — and clearly marks the items we have not yet earned. We do not claim a certification we don't hold.
Last reviewed: May 15, 2026
Current posture
HIPAA-aware platform
LiveWe operate as a HIPAA-aware platform with signed Business Associate Agreements available to every healthcare practice client. Audit trails on every patient-touching interaction.
Read the documentBusiness Associate Agreement (BAA)
LiveStandard BAA is available for execution before any PHI flows through the platform. Required for AI Receptionist and any integration that touches patient data.
Read the documentRead-only EHR access
LiveEHR / FHIR integrations are read-only — ClarioScope never writes back to your chart. Pulls are gated behind a signed BAA + Data-Sharing Addendum.
Read the documentPHI minimization & audit logging
LivePulled records are de-identified at the boundary (names dropped, DOB → year, ZIP truncated, identifiers hashed). Every credential access, EHR pull, and report view lands in an append-only audit log.
Read the documentSOC 2 Type II
In progressAudit window: targeted Q4 2026. Partner selection underway; we will publish the auditor name once locked. Until the audit completes we do not represent ourselves as SOC 2 certified.
Encryption in transit
LiveTLS 1.2 or higher enforced for all traffic to clarioscope.ai and any portal/API surface. Plain HTTP is redirected and the certificate chain is monitored.
Encryption at rest
LiveApplication data (PostgreSQL, object storage, backups) is encrypted at rest using the underlying cloud provider's server-side encryption with provider-managed keys.
Data residency
LiveAll primary data is hosted in US-East via Laravel Cloud on AWS infrastructure. No data leaves the United States unless explicitly required by an authorized integration the practice has connected.
Incident response
LiveWe notify affected practice clients within 24 hours of confirming a security incident, per the terms of the signed BAA. A documented runbook governs containment, eradication, and post-incident review.
Single Sign-On (SSO)
RoadmapSAML / OIDC SSO is on the 2026 roadmap. Today, accounts use email/password with optional email verification.
Deeper detail
EHR & PHI data handling
Read-only EHR access, BAA-gated pulls, PHI minimization at the boundary, de-identified benchmarks, and append-only audit logging.
Subprocessors
Every third party with access to data flowing through the platform — purpose, region, and BAA status.
Security overview
Access controls, key rotation, vulnerability management, and how we off-board employees.
HIPAA notice
Notice of Privacy Practices and how we handle protected health information.
Business Associate Agreement
The standard BAA we execute with every practice before any PHI flows through the platform.
Report a security issue
We take security disclosures seriously. Email security@clarioscope.ai with reproduction steps and any supporting context. We acknowledge within one business day.
Please do not include patient data, screenshots containing PHI, or production credentials in your initial report — we'll arrange a secure channel before that level of detail.
