Your IT team can check it in one read. There is no PHI in the system, and onboarding is contract PDFs under an NDA.
The posture is below and the gap list is directly after it, on the same page on purpose. Your reviewers will find the gaps anyway, and finding them here, in writing, is faster for everyone than finding them three weeks in.
Three questions come up in every review because the answer is a boundary of the product. They sit above the gap list, because a boundary is a design decision.
Four facilities
The reference deployment covers four facilities on a repeatable pipeline. We do not describe it as enterprise-wide.
Out of scope
We do not take in payer or hospital machine-readable files, and we do not hold other organisations' negotiated rates. Comparing you to other health systems would need a transparency feed we do not have.
Out of scope
There is no claims feed, so nothing here is weighted by your actual volumes, and underpayment recovery is not something we measure. We detect quality-at-risk provisions in the contract text; we do not model the economics of value-based arrangements.
This is complete to the best of our knowledge on the questions an IT security review actually asks. If you find something missing from it, that is a defect in this page and we want to hear about it.
| Control | Status today | What we say about it |
|---|---|---|
| Third-party attestation | Not held | SOC 2 is not something we hold, and neither is HITRUST, so there is no certification and no report to send you. Readiness work is underway and we will not describe it as more than that. |
| Identity | Not built | Single sign-on is not built today. MFA is not built today. Authentication is Firebase Auth. If federated identity is a hard requirement for your environment, say so early, because it is a roadmap conversation. |
| Authorisation | Not built | Role-based access control is not implemented, so there is no per-role permission model within a tenancy today. Client writes to contract data are denied outright, which limits the blast radius and is a different control. |
| Reporting and integration | Not built | No scheduled reporting today, and no automated alerting. A warehouse connector is not built either. Data comes out of the interface and by export. |
We would rather your security team read this cold, in advance, than have it become the thing that stalls your managed care team three weeks in.
When the review clears, most systems start with one payer and one negotiation cycle.