Enterprise Security & Compliance
CoverageUnlocked was designed by a healthcare industry insider who understands the security requirements of health systems. Our architecture ensures zero PHI exposure by design.
We never see, store, or transmit protected health information
All patient identifiers are replaced with [BRACKET] placeholders before any data reaches our AI engine. Names, MRNs, dates of birth, addresses — stripped at the source.
Our analysis engine only processes de-identified clinical details: CPT codes, denial reasons, clinical notes (de-identified), and treatment history. Nothing that identifies a patient.
Analysis results are returned in real-time and not persisted on our servers. No PHI database means no PHI breach surface. Zero retained data = zero data risk.
BAA-ready architecture with defense-in-depth
BAA available for execution. Our zero-knowledge architecture minimizes BAA scope.
All API communications use TLS 1.3. Certificate pinning available for enterprise deployments.
AES-256 encryption for any configuration data. No PHI stored at rest.
Role-based access control (RBAC) with SSO integration. Principle of least privilege enforced.
Comprehensive audit trail for all API calls. Immutable logs retained per policy.
Analysis results: not retained. Session metadata: 30 days. Audit logs: 7 years (configurable).
Independent audit planned for Q2 2026
Access controls, encryption, logging, incident response procedures
Point-in-time assessment of security controls design
6-month observation window for operating effectiveness
Independent auditor report on controls operating effectiveness
Enterprise clients receive dedicated API keys with configurable permissions
Per-key rate limiting with configurable thresholds (default: 100 req/min)
Optional IP-based access restrictions for enterprise deployments
Automated key rotation with zero-downtime rollover
Automated anomaly detection on all API endpoints
4-tier severity model (P1-P4) with defined response SLAs
72-hour notification commitment (exceeds HIPAA 60-day requirement)
Root cause analysis and prevention plan for every P1/P2 incident
Hosting
Vercel (AWS)
SOC 2 certified infrastructure
AI Engine
Anthropic Claude
SOC 2 certified, no training on inputs
Database
Supabase
PostgreSQL with RLS, SOC 2 certified
CDN
Vercel Edge
Global edge network, DDoS protection
Have security questions? Our team is happy to walk through our architecture in detail.
Request Security Review