// TRUST CENTER

Protexa

AI-powered HIPAA compliance for healthcare teams.

Framework coverage

The compliance frameworks Protexa is measured against. Status reflects the current attestation state — not a marketing claim.

  • HIPAA Self-attested HIPAA Security & Privacy Rules
  • SOC 2 In progress SOC 2 Type II
  • HITRUST In progress HITRUST CSF

Trust documentation

Policies, procedures, and audit evidence are released under NDA to buyers running a vendor review — request access below.

Audit pack Updated April 15, 2026

SOC 2 Type I attestation, HIPAA Security Rule control mapping, and the latest third-party penetration test summary.

  • Information Security Policy Administrative, physical, and technical safeguards mapped to the HIPAA Security Rule.
    NDA required
  • Incident Response Plan Detection, triage, breach classification, and the 24-hour customer notification SLA.
    NDA required
  • Access Control Policy Role-based access, least-privilege provisioning, and quarterly access reviews.
    NDA required
  • Business Continuity & Disaster Recovery Plan RTO/RPO targets, backup cadence, and failover procedures.
    NDA required
  • Data Retention & Disposal Policy Retention schedules and cryptographic destruction of PHI at end of life.
    NDA required
Request access under NDA

Subprocessors

The third-party services that process data on Protexa's behalf. Each operates under a signed agreement; the list is updated when it changes.

  • Supabase Managed Postgres database, authentication, file storage, and serverless functions.
    United States BAA + DPA
  • Vercel Application hosting, edge content delivery, and preview deployments.
    United States (global edge) BAA + DPA
  • OpenAI Large language model inference for AI agents and document analysis.
    United States BAA + DPA
  • Anthropic Large language model inference (Claude) for AI agents and compliance analysis.
    United States BAA + DPA
  • Deepgram Speech-to-text transcription of ambient clinical audio for the documentation workflow.
    United States BAA + DPA

Security contact

Running a vendor risk assessment? Reach the team that owns Protexa's security posture directly.

[email protected]