SECURITY & DATA PROTECTION

Built for PHI from the first line.

CareCompile processes some of the most sensitive data a hospital produces. This page describes, plainly, how that data is protected — what we encrypt, what we log, where your data can live, and what our models are and are not allowed to do with it.

01

Encryption, everywhere

All PHI is encrypted at rest with AES-256 and in transit with TLS 1.3. HL7 v2.x traffic reaches the platform over an HTTPS bridge; FHIR R4 exchanges run over authenticated TLS endpoints. Certificate health is monitored daily with automated renewal.

02

Your data stays yours

Patient data never trains anyone's model — not ours, not a vendor's. The engine is model-agnostic by design: proprietary models, open-source models, or your own, in the cloud or fully on-premises. For field and defense deployments, the intelligence layer carries de-identified data only.

03

Every decision, auditable

Every alert, agent finding, and staged order is written to a tamper-evident audit trail with 7-year retention. When someone asks why the system said what it said, there is always an answer — with the evidence attached.

04

Deployment options

Cloud, on-premises, or fully air-gapped. On-premises deployments keep PHI inside your network boundary end to end — the same engine runs on local hardware with local models, no external calls required.

05

Operational safeguards

  • Role-based access; least-privilege service accounts
  • Daily automated database backups
  • Host firewall with default-deny inbound policy
  • Dependency and configuration review on every release
  • 145-check validation suite re-run on every change
06

Compliance posture

CareCompile is built to HIPAA requirements for PHI handling, and a Business Associate Agreement is available for pilots and production deployments. SOC 2 alignment work is underway as part of our pre-commercial compliance program.

CareCompile is a non-diagnostic clinical decision support tool — advisory only, with the licensed clinician always in charge.

Responsible disclosure

Found a vulnerability? We want to hear about it — quietly and quickly. Email security@carecompile.com with details and we will respond within one business day. Please do not test against systems containing data you do not own; MediFlow-generated synthetic environments are available on request for security research.

BAA requests

To request a Business Associate Agreement or our security documentation for procurement review, email hello@carecompile.com.

Note — This page summarizes CareCompile's security architecture as of August 2026. It is provided for informational purposes and does not by itself constitute a contractual commitment; contractual terms are defined in the BAA and service agreement.