Trust center

Built to be audited.

Authora is engineered around the constraints of a regulated industry. Every claim on this page links to evidence — current certifications, in-progress audits with dates, and the gaps we will not pretend to have closed.

Uptime99.97%
Pen-test cadenceQuarterly
Data residencyUS
EncryptionAES-256 / TLS 1.3
Retention7 years WORM
Audit-log integritySHA-256 chained
Certifications & audits

What is true today, what is in flight, and when each completes.

StandardScopeStatusAuditorLast verifiedNext milestone
HIPAA Security RulePlatformConformantSelf-attested2026-04-12Q3 2026 external attestation (Vanta)
SOC 2 Type IPlatformIn progressVanta + auditor TBDEvidence collectionTarget Q3 2026
SOC 2 Type IIPlatformPlannedTarget Q1 2027
HITRUST CSFPlatformPlannedTrack started Q2 2026
NCQA UM AccreditationDelegated UMPlannedNCQAApplication open Q4 2026
CAQH CORE CertificationX12 278 / 270 / 271In progressCAQHTest phaseTarget Q3 2026
FedRAMP ModeratePlatformRoadmapTarget FY27 if first government customer signs
ISO 27001PlatformRoadmapPairs with SOC 2 Type II
WCAG 2.2 AAWebConformantaxe-core + Deque manual2026-05-01Q3 2026 external audit
Section 508WebConformantSelf-attested2026-05-01Pairs with WCAG external
Data protection

PHI at rest, in transit, and in process.

Encryption

At rest, AES-256-GCM with customer-managed keys via AWS KMS as an option, on a 90-day rotation. In transit, TLS 1.3 minimum across every internal and external hop. In process, PHI is handled inside memory-encrypted enclaves on dedicated worker pools. No customer PHI is ever logged to disk in plaintext, and no analytics pipeline receives identifiable data.

Data residency

All PHI lives in us-east-2 (Ohio). Multi-region failover is restricted to US regions. No data ever leaves the United States. Customer-controlled deletion is honored within 30 days of contract termination, with a signed certificate of destruction delivered to the customer's compliance officer.

Access control

Role-based access with strict tenant isolation enforced at the database, application, and audit-log layers. Break-glass access for engineering requires dual-control approval, time-bound credentials, and an immutable audit entry. No engineer touches a single byte of customer PHI without a logged, dual-approved access ticket — including the founders.

Audit & accountability

Every read, every write, every decision — accountable.

Tamper-evident audit log

Every read, every write, every decision, every integration call is captured. Entries are SHA-256 chained per-tenant, delivered daily by SFTP to a customer-controlled S3 bucket with a customer-managed KMS key. 7-year retention. The chain can be independently verified — we publish the verification tool.

Right of inspection

Your named compliance officer can request a full export of any slice of the audit log — by patient, by case, by date range, by integration — and receive it within a 24-hour SLA. No fee, no negotiation. This is part of the BAA, not a paid add-on.

Incident disclosure

Material security events are disclosed in writing within 24 hours. Breaches affecting PHI are disclosed within 60 days as required by the HIPAA Breach Notification Rule. The status page is public and historical; nothing is quietly redacted.

BAA & legal
Business Associate Agreement (BAA)

Authora executes a BAA before any production data flow. Our template is based on the OCR sample, with payer-specific addenda available for the major commercial plans. Download our standard BAA template for legal review prior to procurement.

Disclosed gaps — what is not yet true

The section that wins trust.

  • SOC 2 Type II will not complete until Q1 2027. Until then, customers should reference our SOC 2 Type I evidence pack and our HIPAA self-attestation.

  • FedRAMP authorization is on the roadmap pending a government customer LOI. Federal use cases are gated on this and we will not pretend otherwise.

  • Authora has not yet completed an independent NCQA UM audit. Delegated UM operations contracts will be conditioned on customer-supervised parallel review for the first 90 days.

Contacts

Real mailboxes. Real humans on the other side.