Trust & Security

ClarioScope is built for healthcare. This page lists every certification, control, and posture we publicly commit to — and clearly marks the items we have not yet earned. We do not claim a certification we don't hold.

Last reviewed: May 15, 2026

Current posture

HIPAA-aware platform

Live

We operate as a HIPAA-aware platform with signed Business Associate Agreements available to every healthcare practice client. Audit trails on every patient-touching interaction.

Read the document

Business Associate Agreement (BAA)

Live

Standard BAA is available for execution before any PHI flows through the platform. Required for AI Receptionist and any integration that touches patient data.

Read the document

Read-only EHR access

Live

EHR / FHIR integrations are read-only — ClarioScope never writes back to your chart. Pulls are gated behind a signed BAA + Data-Sharing Addendum.

Read the document

PHI minimization & audit logging

Live

Pulled records are de-identified at the boundary (names dropped, DOB → year, ZIP truncated, identifiers hashed). Every credential access, EHR pull, and report view lands in an append-only audit log.

Read the document

SOC 2 Type II

In progress

Audit window: targeted Q4 2026. Partner selection underway; we will publish the auditor name once locked. Until the audit completes we do not represent ourselves as SOC 2 certified.

Encryption in transit

Live

TLS 1.2 or higher enforced for all traffic to clarioscope.ai and any portal/API surface. Plain HTTP is redirected and the certificate chain is monitored.

Encryption at rest

Live

Application data (PostgreSQL, object storage, backups) is encrypted at rest using the underlying cloud provider's server-side encryption with provider-managed keys.

Data residency

Live

All primary data is hosted in US-East via Laravel Cloud on AWS infrastructure. No data leaves the United States unless explicitly required by an authorized integration the practice has connected.

Incident response

Live

We notify affected practice clients within 24 hours of confirming a security incident, per the terms of the signed BAA. A documented runbook governs containment, eradication, and post-incident review.

Single Sign-On (SSO)

Roadmap

SAML / OIDC SSO is on the 2026 roadmap. Today, accounts use email/password with optional email verification.

Report a security issue

We take security disclosures seriously. Email security@clarioscope.ai with reproduction steps and any supporting context. We acknowledge within one business day.

Please do not include patient data, screenshots containing PHI, or production credentials in your initial report — we'll arrange a secure channel before that level of detail.