Your data. Your hardware. If you want it.
We treat your PHI like it is our own. And if you would rather it never leave your building, you can self-host the whole stack.
Every action, logged. Every role, scoped.
Users, roles, permissions, and the access log.

Sign in the way security teams prefer.

Security primitives you can audit.
HIPAA-aligned by default
Designed to the HIPAA Security Rule; a BAA is part of every customer agreement at launch. Encryption at rest (AES-256) and in transit (TLS 1.3). Logged, signed, retained.
Role-based access and row-level security
Access control on every endpoint. Database-level row isolation so a misconfigured query cannot cross tenants.
Full audit trail
Every access, every change, every export, recorded with user, time, IP and prior value. Searchable.
Per-user MFA and security keys
TOTP or hardware key, enforced at the organization level. SSO available for groups.
Encrypted backups
Point-in-time recovery. Backups encrypted at rest with customer-managed keys for self-hosted deployments.
Self-host option
The Docker Compose stack runs on your hardware. The patient record never leaves the building.
Your data, your export, your rules.
Every chart, every claim, every note is yours. Export at any time in open formats. No proprietary lock-in. No “we’ll get back to you in ninety days.” If you decide to leave, you leave with everything.
Want the security review packet?
Architecture diagrams, the SOC 2 roadmap, the BAA template, and the self-host runbook.