Security & compliance

HIPAA on a single AWS BAA. No exceptions.

This page is the full posture for IT, compliance, and legal review. The landing page keeps the short version; the long version lives here so your procurement team has everything they need in one place.

Request the BAA templateTalk to security
Vendors & BAA
Single-vendor BAA

One AWS BAA covers Cognito, Aurora, S3, KMS, Bedrock, Lambda, CloudFront, and Amazon Location.

No third-party PHI processors

PHI never leaves AWS. No OpenAI, no third-party analytics, no foreign sub-processors.

Encryption
Customer-managed KMS

alias/sereniq-{stage}-phi · yearly rotation · AAD-bound to record context.

Per-field PHI encryption

SSN, Medicaid ID, and Medicare ID are encrypted with per-record AAD context.

Aurora Serverless v2 in private subnets

No public ingress. Egress only through application identity.

Access control
Row-Level Security

FORCE RLS on every tenant-scoped table · default-deny.

Home-scoping above RLS

DSPs and nurses see only assigned homes via staff_assignments.

MFA enforced

TOTP required for admin, supervisor, nurse_lpn, and nurse_rn.

Cognito Advanced Security

Enforced — risk-based challenges on anomalous sign-in.

Audit + observability
Immutable audit log

Every state change captures userId, IP, user-agent, and a non-PHI after-blob.

No PHI in logs or URLs

Zod validation everywhere. CSV exports strip formula leaders to defeat spreadsheet injection.

Destructive admin actions mirrored

High-impact admin operations are also written to a separate ops bucket.

AI safety
HIPAA-eligible model hosting

AI features run on AWS Bedrock, inside the same single-vendor BAA.

Untrusted content boundaries

User-provided narratives are wrapped in tagged blocks. Raw input never concatenates into a system prompt.

Per-agency token cap

A daily cap bounds worst-case AI spend per tenant.

Still have questions? We’ll answer them.

Send your questionnaire, your CISO’s checklist, or your auditor’s data-flow request. A founder will reply within one business day.

Book a demo