Protexa
AI-powered HIPAA compliance for healthcare teams.
Framework coverage
The compliance frameworks Protexa is measured against. Status reflects the current attestation state — not a marketing claim.
- HIPAA Self-attested HIPAA Security & Privacy Rules
- SOC 2 In progress SOC 2 Type II
- HITRUST In progress HITRUST CSF
Trust documentation
Policies, procedures, and audit evidence are released under NDA to buyers running a vendor review — request access below.
Audit pack
Updated April 15, 2026
SOC 2 Type I attestation, HIPAA Security Rule control mapping, and the latest third-party penetration test summary.
- Information Security Policy Administrative, physical, and technical safeguards mapped to the HIPAA Security Rule.NDA required
- Incident Response Plan Detection, triage, breach classification, and the 24-hour customer notification SLA.NDA required
- Access Control Policy Role-based access, least-privilege provisioning, and quarterly access reviews.NDA required
- Business Continuity & Disaster Recovery Plan RTO/RPO targets, backup cadence, and failover procedures.NDA required
- Data Retention & Disposal Policy Retention schedules and cryptographic destruction of PHI at end of life.NDA required
Subprocessors
The third-party services that process data on Protexa's behalf. Each operates under a signed agreement; the list is updated when it changes.
- Supabase Managed Postgres database, authentication, file storage, and serverless functions.
- Vercel Application hosting, edge content delivery, and preview deployments.
- OpenAI Large language model inference for AI agents and document analysis.
- Anthropic Large language model inference (Claude) for AI agents and compliance analysis.
- Deepgram Speech-to-text transcription of ambient clinical audio for the documentation workflow.
Security contact
Running a vendor risk assessment? Reach the team that owns Protexa's security posture directly.
[email protected]