Security & Trust

Built for the data a health plan can't afford to lose.

Avertyn handles claims and dispute data on behalf of payers and TPAs. Below is a specific account of the controls that are live today and the assurances that are in progress — no vague promises, no compliance theater.

Live today

Controls in production now.

Live

Tenant isolation

Every data path is scoped to a single organization with database row-level security. One customer's claims are never reachable from another's session — enforced at the data layer, not just the app.

Live

Encryption

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256) across the managed database, storage, and backups.

Live

Tamper-evident audit trail

Every automated action is written to a SHA-256 hash-chained ledger with its rationale and legal citations, independently verifiable and retained for at least six years.

Live

Authentication & access

Multi-factor authentication, least-privilege org-scoped access, and plan-level role controls. SSO / SCIM available for enterprise directories.

Live

Governed AI agent

The autonomous agent acts only through typed, enumerated actions, with human-in-the-loop approval, dry-run, money caps, and reversibility. Every decision is explainable and logged.

Live

Managed, audited infrastructure

Hosted on SOC 2-audited cloud infrastructure with point-in-time recovery and continuous security monitoring.

In progress

Assurances underway — and where they stand.

In progress

HIPAA / BAA

A Business Associate Agreement is available. Real protected health information is handled only in a HIPAA-configured environment under a signed BAA; the demo uses synthetic data only.

In progress

SOC 2 Type II

Readiness is underway. We inherit SOC 2 controls from our infrastructure today; our own Type II examination is in progress. Report available to qualified customers under NDA once complete.

Planned

HITRUST

On the roadmap after SOC 2, for customers whose programs require it.

Sub-processors

Who touches the data, and how it's covered.

We engage a small set of vendors to deliver the service. Each that may handle protected data is covered by a BAA or equivalent; the list is kept current.

Sub-processorPurposeDataSafeguard
Supabase (on AWS)Primary database, authentication, file storageApplication data, incl. ePHI for live tenantsEncryption at rest + TLS; row-level isolation; BAA for PHI
Amazon Web ServicesUnderlying compute, storage, networkSame, as infrastructureAWS BAA; SOC 2 / ISO audited
VercelHosting of the web applicationRequest metadata; renders data client-sideTLS; no PHI stored at rest
Anthropic (Claude)AI drafting & document summarizationCase facts only when a customer enables AI featuresZero-retention / no-training terms; BAA before any PHI, else de-identified input

Minimum necessary, by default

The agent and any downstream model receive the least data required for a task, and we prefer de-identified input wherever the work allows. Push and email notifications are kept free of clinical detail.

Governance

Incident response & contact.

We maintain an incident-response process and, under a signed BAA, provide breach notification consistent with the HIPAA Breach Notification Rule. Named Security and Privacy Officers own our controls and review them at least annually and on material change.

Security questions, a copy of our security summary, or to report a concern: security@avertyn.com.

Ready to run your own claims?

Start with a free exposure view on synthetic data. When you're ready for live data, we complete the MSA and BAA first.

See your exposure — free View pricing