Skip to content
Skip to content

Trust & security

Built for healthcare data from day one

Embed Care owns the patient record, so security is our responsibility — not a vendor’s afterthought. Here’s how we protect it.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest. Secrets in a managed vault, never in code.

Tenant isolation

Postgres row-level security keys every record to its tenant — isolation is a database invariant, not a query convention.

Least privilege + MFA

Role-based access (admin / partner / clinician / patient), MFA on internal access, scoped API keys per tenant.

Audit everything

Every access to a record is logged with who, what, and when — available to partners and exportable.

Subprocessors

The services that process data on our behalf — each under a BAA where PHI is involved.

ServiceRoleBAA
Supabase / PostgresPrimary datastore + RLSYes
TwilioSMS / voiceYes
SendGridTransactional emailYes
StripePayments + payoutsN/A (no PHI)
Pharmacy / EMR adaptersFulfillment + recordsPer partner

Security program

The controls below operate in production today; the attestations beneath them are being formalized.

Operating today

  • Security Risk Assessment
  • BAAs with every subprocessor
  • Tenant isolation + audit logging in production

Attestations underway

  1. 1Third-party penetration test
  2. 2SOC 2 Type II

Need our security package or a BAA for diligence? We’ll walk your team through it.

Talk to us

This page describes the production security posture. The interactive demo uses synthetic data only — no PHI.

Ready to make this your brand?

Plug in your audience. We run the clinic. You keep the revenue.