Skip to content
Skip to content

Trust & security

Built for healthcare data from day one

EmbedCare owns the patient record, so security is our responsibility, not a vendor’s afterthought. Here’s how we protect it.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest. Secrets in a managed vault, never in code.

Tenant isolation

Postgres row-level security keys every record to its tenant; isolation is a database invariant, not a query convention.

Least privilege + MFA

Role-based access (admin / partner / clinician / patient), MFA on internal access, scoped API keys per tenant.

Audit everything

Every access to a record is logged with who, what, and when, available to partners and exportable.

Subprocessors

The services that process data on our behalf, each under a BAA where PHI is involved.

Subprocessors that process data on our behalf — one row per service, with its BAA status
ServiceRoleBAA
Supabase / PostgresPrimary datastore + RLSYes
TwilioSMS / voiceYes
SendGridTransactional emailYes
StripePayments + payoutsN/A (no PHI)
Pharmacy / EMR adaptersFulfillment + recordsPer partner

Security program

The controls below operate in production today; the attestations beneath them are being formalized.

Operating today

  • Security Risk Assessment
  • BAAs with every subprocessor
  • Tenant isolation + audit logging in production

Attestations underway

  1. 1Third-party penetration test
  2. 2SOC 2 Type II

Need our security package or a BAA for diligence? We’ll walk your team through it.

Talk to us

This page describes the production security posture. The interactive demo uses synthetic data only, no PHI.

Ready to make this your brand?

Plug in your audience. We run the clinic. You keep the revenue.