Trust is the architecture.
Automate Medical is built on the assumption that PHI never leaves your trust boundary, that every inference is auditable, and that the audit log is the source of truth. The platform is HIPAA-aware end-to-end, BAA-covered, and continuously validated.
How we keep PHI safe.
HIPAA-aware architecture
PHI is encrypted at rest (AES-256) and in transit (TLS 1.2+). Role-based access control with SSO, SAML, and OIDC. PHI never leaves your trust boundary.
BAA program
Business Associate Agreement is on file for every enterprise customer. Subcontractor BAAs in place with every LLM provider we route through.
Immutable audit log
Every model version, every inference, every access — timestamped, immutable, retention-aligned to HIPAA. 6-year retention on inference logs.
SOC 2 Type II (in flight)
Security, availability, and confidentiality controls audited annually. Report available under NDA on request.
Continuous validation
Production drift monitoring on every release. Anomalous drift triggers re-validation. Audit log on every inference.
No public LLM endpoints on PHI
We never route PHI through public ChatGPT, Claude.ai, or Gemini app endpoints. Only BAA-covered LLM providers, in a customer-controlled tenancy.
Your data stays yours.
We do not sell customer data. We do not use customer data to train foundation models. Every inference is auditable, every access is logged, every BAA is on file. If a regulator asks, you have the answer.
Report a vulnerability: security@automate-medical.com
Request our security pack.
SOC 2 report, BAA template, penetration test summary, and architecture diagrams. Under NDA.