Avertyn handles claims and dispute data on behalf of payers and TPAs. Below is a specific account of the controls that are live today and the assurances that are in progress — no vague promises, no compliance theater.
Every data path is scoped to a single organization with database row-level security. One customer's claims are never reachable from another's session — enforced at the data layer, not just the app.
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256) across the managed database, storage, and backups.
Every automated action is written to a SHA-256 hash-chained ledger with its rationale and legal citations, independently verifiable and retained for at least six years.
Multi-factor authentication, least-privilege org-scoped access, and plan-level role controls. SSO / SCIM available for enterprise directories.
The autonomous agent acts only through typed, enumerated actions, with human-in-the-loop approval, dry-run, money caps, and reversibility. Every decision is explainable and logged.
Hosted on SOC 2-audited cloud infrastructure with point-in-time recovery and continuous security monitoring.
A Business Associate Agreement is available. Real protected health information is handled only in a HIPAA-configured environment under a signed BAA; the demo uses synthetic data only.
Readiness is underway. We inherit SOC 2 controls from our infrastructure today; our own Type II examination is in progress. Report available to qualified customers under NDA once complete.
On the roadmap after SOC 2, for customers whose programs require it.
We engage a small set of vendors to deliver the service. Each that may handle protected data is covered by a BAA or equivalent; the list is kept current.
| Sub-processor | Purpose | Data | Safeguard |
|---|---|---|---|
| Supabase (on AWS) | Primary database, authentication, file storage | Application data, incl. ePHI for live tenants | Encryption at rest + TLS; row-level isolation; BAA for PHI |
| Amazon Web Services | Underlying compute, storage, network | Same, as infrastructure | AWS BAA; SOC 2 / ISO audited |
| Vercel | Hosting of the web application | Request metadata; renders data client-side | TLS; no PHI stored at rest |
| Anthropic (Claude) | AI drafting & document summarization | Case facts only when a customer enables AI features | Zero-retention / no-training terms; BAA before any PHI, else de-identified input |
The agent and any downstream model receive the least data required for a task, and we prefer de-identified input wherever the work allows. Push and email notifications are kept free of clinical detail.
We maintain an incident-response process and, under a signed BAA, provide breach notification consistent with the HIPAA Breach Notification Rule. Named Security and Privacy Officers own our controls and review them at least annually and on material change.
Security questions, a copy of our security summary, or to report a concern: security@avertyn.com.
Start with a free exposure view on synthetic data. When you're ready for live data, we complete the MSA and BAA first.