Trust & security
Built for healthcare data from day one
EmbedCare owns the patient record, so security is our responsibility, not a vendor’s afterthought. Here’s how we protect it.
Encryption everywhere
TLS 1.2+ in transit, AES-256 at rest. Secrets in a managed vault, never in code.
Tenant isolation
Postgres row-level security keys every record to its tenant; isolation is a database invariant, not a query convention.
Least privilege + MFA
Role-based access (admin / partner / clinician / patient), MFA on internal access, scoped API keys per tenant.
Audit everything
Every access to a record is logged with who, what, and when, available to partners and exportable.
Subprocessors
The services that process data on our behalf, each under a BAA where PHI is involved.
| Service | Role | BAA |
|---|---|---|
| Supabase / Postgres | Primary datastore + RLS | Yes |
| Twilio | SMS / voice | Yes |
| SendGrid | Transactional email | Yes |
| Stripe | Payments + payouts | N/A (no PHI) |
| Pharmacy / EMR adapters | Fulfillment + records | Per partner |
Security program
The controls below operate in production today; the attestations beneath them are being formalized.
Operating today
- Security Risk Assessment
- BAAs with every subprocessor
- Tenant isolation + audit logging in production
Attestations underway
- 1Third-party penetration test
- 2SOC 2 Type II
Need our security package or a BAA for diligence? We’ll walk your team through it.
This page describes the production security posture. The interactive demo uses synthetic data only, no PHI.
Ready to make this your brand?
Plug in your audience. We run the clinic. You keep the revenue.