Trust Center

Security designed for healthcare

Designed to support HIPAA-compliant healthcare operations. BAA available for covered entities. SOC 2 readiness underway.

Architecture overview

SovaCare is a multi-tenant clinical platform: Next.js application, FastAPI services, and PostgreSQL with tenant isolation. Authenticated clinical applications are separate from the public marketing site.

Encryption

TLS 1.2+ in transit. AES-256 encryption at rest for patient data stores.

Access controls

Give each staff member access only to what they need. Role-based permissions, session controls, and least-privilege defaults.

Authentication

Credentialed access with support for multi-factor authentication. Enterprise identity (SSO) is available for quoted deployments.

Audit logging

Access, modifications, and authentication events are logged. Retention follows SovaCare policy and applicable contractual requirements—not a claimed HIPAA seven-year mandate.

Backup and disaster recovery

Database backups and recovery procedures are maintained for the production environment. Recovery objectives are defined per customer Order Form for enterprise agreements.

Data residency

Production clinical workloads are hosted in United States Azure regions unless an Order Form specifies otherwise.

Subprocessors

PHI-processing subprocessors (such as Microsoft Azure) are engaged under appropriate contractual assurances. Vendors that never receive PHI—including public-site analytics providers—are not treated as business associates.

Vulnerability management

Dependencies and infrastructure are reviewed on an ongoing basis. Penetration testing is performed as part of the security program; reports are available to customers under NDA.

Incident response

Security incidents involving PHI are handled under the BAA, including notification to the covered entity without unreasonable delay.

BAA and SOC 2

  • BAA available for covered entities
  • SOC 2 readiness underway — this is not a completed SOC 2 Type I or Type II report
  • HIPAA practices: HIPAA & PHI Practices

Security contact and disclosure

Report vulnerabilities or security incidents to security@sovacare.health. For BAA and compliance questions, use admin@sovacare.health.

Please do not include PHI in unsolicited email. Use the covered-entity incident channel once a BAA is in place.