Security · Trust posture

How your data stays
your data.

Protexa is built for healthcare. Security is not an afterthought bolted onto a generic GRC platform — every control here was designed under HIPAA, mapped to specific Security Rule sections, and verifiable on request.

// CHAPTER 01 · LIVE POSTURE

What's protecting your data, right now.

The controls that matter — encryption, identity, audit, isolation — run continuously. Not "documented as a policy" — actually enforced in code. The panel on the right is the live state, not a screenshot.

Live security posture 6 controls active
  • Encryption at rest AES-256
  • Encryption in transit TLS 1.3
  • Multi-factor authentication Enforced · admin + officer
  • Single sign-on SAML 2.0 · Okta · Azure AD · Google
  • Audit log retention Forever · immutable, append-only
  • Tenant isolation Per-customer · row-level security
Last verified continuously Next attestation on request
// CHAPTER 02 · ARCHITECTURE

Built for healthcare. Isolated by design.

Tenant isolation by row-level security

Every customer organization runs in a logically isolated namespace enforced at the database row level. There is no shared data across tenants. A query mis-attributed to the wrong organization fails closed — rejected before the database touches a single row.

PHI minimization across every workflow

The HIPAA minimum-necessary principle applied at every step, not just where auditors check. Ambient transcripts are processed in memory and discarded after extraction; only the structured OASIS items + clinician attestation persist.

Subprocessor scope boundaries

Cloud infrastructure (Supabase, Vercel) operates under signed BAA. Subprocessors handle compute and storage only — they never receive PHI in plain text and have no application-level access. Full subprocessor list available on request.

HIPAA Security Rule mapped to code

§164.308 administrative safeguards · §164.312 technical safeguards · §164.314 organizational requirements. Each control mapped to specific platform features and audit-log events. The mapping is itself an artifact we provide during due diligence.

// CHAPTER 03 · INCIDENT RESPONSE

If something goes wrong, you find out fast.

Healthcare buyers don't trust vendors who promise nothing will go wrong. They trust vendors who can show what happens when it does.

Detection

Continuous monitoring across application, infrastructure, and access layers. Anomaly detection on access patterns, failed auth attempts, and configuration drift.

Triage

Breach Responder agent classifies severity and scope automatically. Material incidents (PHI exposure, integrity loss, availability >4h) escalate to a 24-hour customer notification SLA — well inside the §164.408 60-day ceiling.

Forensics

Immutable audit log provides a forensic timeline back to first event. Bundle assembled automatically: affected records, timeline, root cause, remediation steps, breach notification draft.

Disclosure

Public disclosure for material incidents posted within the customer notification window. Pattern modeled on Drata's incident transparency — say what happened, what we did, what we changed.

// CHAPTER 04 · DUE DILIGENCE

What we'll send you, on request.

Your VRA process probably has a checklist. Most of what you need is on this list. What's not — tell us, and we'll either send it, sign it, or tell you honestly when it'll be ready.

  • Business Associate Agreement available Signed copy provided before go-live. Covers permitted uses, safeguards, breach notification SLAs, subprocessor flow-down.
  • Security questionnaire response available Pre-filled SIG Lite, CAIQ, or your custom questionnaire. Returned within 5 business days.
  • Data Processing Agreement (DPA) available GDPR-aligned terms for organizations with EU-resident data subjects. Signed at order or as an amendment.
  • Subprocessor list available Current subprocessors with purpose, region, and BAA status. Updated when the list changes.
  • SOC 2 Type II report in progress Audit in progress. Type I attestation available now; Type II report under examination — ETA shared on request.
Request security documentation →

Or email [email protected] directly with your security questionnaire attached.