SECURITY & COMPLIANCE

Built for regulated
healthcare environments.

Vindicate is designed from the ground up to meet the security and privacy requirements of enterprise healthcare organizations. This page documents every relevant security control.

DATA FLOW

What happens to your document.

01

Encrypted upload

Your document is uploaded over TLS 1.3. No unencrypted channel is ever used. The upload goes directly to our processing environment.

02

Processing in isolated environment

The document is analyzed against our regulatory index in an isolated processing environment. No human reviews your document.

03

Source document deleted

After analysis is complete, the source document is permanently deleted from our processing environment. We retain only the structured analysis output.

04

Analysis returned to you

The analysis output — citations, identified issues, recommendations — is returned to your session. You control this output.

05

Session output cleared on request

You can delete your analysis history at any time. We do not retain data that you have deleted.

SECURITY CONTROLS

Every control, documented.

HIPAA Data Minimization

Documents are processed and immediately discarded. No PHI stored. No personal health information retained after analysis. We apply HIPAA data minimization principles to every document we process.

When you upload a document, it is sent over encrypted TLS to our processing environment, analyzed against our regulatory index, and the raw document is permanently deleted. We retain only the output of the analysis — never the source document or its contents.

No Third-Party Sharing

Your documents and queries are never shared with insurers, health systems, or any third party. Vindicate has no commercial relationship with payers, providers, or any healthcare entity.

We are structurally independent. We have no data-sharing agreements with insurance companies, hospital systems, or billing companies. Your insurer will never know you used Vindicate.

BAA Available

Business Associate Agreements available for enterprise deployments requiring formal HIPAA documentation. We execute BAAs with qualifying healthcare organizations.

If your organization is a Covered Entity or Business Associate under HIPAA, we can execute a Business Associate Agreement before you begin using Vindicate. Contact us at support@getvindicate.com to initiate the BAA process.

Encrypted in Transit

All document uploads and API communications are encrypted with TLS 1.3. Enterprise-grade security for sensitive healthcare data at every point of transfer.

We enforce TLS 1.3 minimum for all connections. There is no fallback to unencrypted channels. Our infrastructure is hosted on SOC 2 certified cloud providers.

No Model Training on Customer Data

Your documents and queries are never used to train AI models. What you upload stays yours — it is not used to improve any model, ever.

We do not use customer data for model training under any circumstances. We have contractual protections in our AI provider agreements ensuring your data is not used for training purposes.

Zero Document Retention

We do not retain uploaded documents after analysis is complete. There is no document storage, no document history stored on our servers.

Document retention policy: none. After analysis, the source document is deleted from our processing environment. Only the structured analysis output is retained for your session. You can delete that output at any time.

Need a BAA or security review?

We support enterprise security reviews and execute Business Associate Agreements for qualifying healthcare organizations. Contact us to begin.

Request a Demosupport@getvindicate.com