Security & compliance

Built to the standards legal and medical data demand.

ChartInsight protects records through their whole lifecycle with independently audited controls, restricted access, encryption, and continuous monitoring.

HIPAA
Compliant program, BAAs executed
SOC 2
Type II, independently examined
AES-256
At rest · TLS 1.3 in transit
Zero
Model training on customer data
HIPAA compliantBAAs executed
SOC 2 Type IIIndependent controls review
AES-256 at restEncryption for stored records
TLS 1.3 in transitEncrypted connections
Defensible by design

Three assurances we put in writing.

01

Your records are never used to train any model; yours or anyone else’s.

Enforced contractually with our cloud and AI providers, and restated in every agreement we sign.

02

PHI is accessible only by users you authorize.

Account roles and per-record sharing on your side. Least privilege, explicit permission, and logged access on ours.

03

Records can be permanently erased at any time.

Configurable expiration on every record. Erasure hard-deletes documents, outputs, vectors, and chats.

Private AI by design

The AI works for your matter, not on your data.

Uploaded records, prompts, extracted information, and generated outputs are not used by ChartInsight or its subprocessors to train or improve AI models. Each customer’s data is logically isolated through tenant-scoped authorization and record-level access controls.

Model versions may change as security, quality, and reliability improve. The same privacy and contractual requirements always apply.

Tenant-scoped authorization

Access decisions stay within the customer tenant.

Record-level controls

Sharing supports private, team-wide, and specific-user scopes.

No training on prompts or outputs

Customer records, prompts, and outputs are not used for model training.

Contractual enforcement

Cloud and AI providers are bound by contractual data protections.

Infrastructure and operations

Security controls you can inspect.

US-based AWS infrastructure

Production runs on AWS infrastructure in the United States.

Private subnets

Production services run in private subnets without public IP addresses.

WAF and malware scanning

AWS WAF managed rules protect the edge and uploaded objects are malware scanned.

Secrets Manager rotation

AWS Secrets Manager stores credentials with automated rotation.

Isolated environments

Production and non-production networks are isolated.

Continuous monitoring

CloudTrail, Config, Security Hub, and Vanta provide ongoing evidence and monitoring.

Retention controls

Configurable record expiration supports hard-delete erasure.

Every claim on this page is documented.

Current SOC 2 reports, security policies, and attestations are available through the ChartInsight Trust Center.

Cookie Preferences

We use cookies and similar technologies to operate our website and analyze traffic. We do not sell your personal information. Click "Cookie Settings" to manage your preferences or learn more about how we use your data.