TRUST-AC-01
Tenant-scoped authorization boundaries
Framework: OWASP API Security / ASVS
Status: IMPLEMENTED
Request authentication + tenant header binding + scope checks on public API routes.
Customer Trust Center
EncounterReady enforces tenant-scoped API auth, signed webhooks with replay controls, and immutable audit evidence across integration workflows.
TRUST-AC-01
Framework: OWASP API Security / ASVS
Status: IMPLEMENTED
Request authentication + tenant header binding + scope checks on public API routes.
TRUST-WH-02
Framework: OWASP API8:2023
Status: IMPLEMENTED
HMAC-SHA256 signatures, idempotency replay ledger, retry/backoff delivery logs.
TRUST-AI-03
Framework: NIST AI RMF 1.0 + GenAI Profile
Status: MONITORING
Human oversight and non-PHI telemetry guardrails documented for AI-assisted workflows.
TRUST-DR-04
Framework: NIST Privacy Framework
Status: IMPLEMENTED
Tenant self-service request lifecycle with immutable audit evidence.
Last 30 days
Availability 99.97% (SLA target 99.9%)
Incidents: 1
Single partial degradation in non-clinical reporting path.
Last 90 days
Availability 99.95% (SLA target 99.9%)
Incidents: 2
No data integrity incidents and no tenant boundary violations.
| Vendor | Service | Data categories |
|---|---|---|
Google Cloud US regional | Hosting, storage, managed runtime | Application metadata, Audit evidence, Customer configurationpolicy |
Stripe US/EU | Billing and subscription lifecycle | Billing profile metadata, Invoice and subscription recordspolicy |
Postmark US | Transactional email delivery | Operational contact address, Message delivery telemetrypolicy |
v2026.1
Business associate terms, breach obligations, and safeguard commitments for PHI workflows.
Open documentv2026.1
Processing instructions, data rights handling, and transfer protections for tenant data.
Open documentv2026.3
Security controls, access model, and incident response baseline.
Open documentv2026.3
How tenants request exports and deletion, approval workflow, and evidence trail.
Open documentv2026.3
State/specialty legal template lifecycle controls, review cadence, and required-form gates.
Open documentv2026.3
Draft-only AI policy with human review, risk gating, and governance controls.
Open documentv2026.3
Current subprocessors, data categories processed, and review cadence.
Open document