Trust center
A plain statement of the safeguards and assurance evidence EttaCare can support today.
Security practices
EttaCare uses encryption in transit and at rest, role- and relationship-based access controls, append-only audit evidence, malware scanning, private networking and tested fail-closed production configuration. No seal or technical control eliminates all risk.
Health-care privacy
EttaCare supports practices operating under HIPAA and state health-care privacy requirements. Practice and vendor business associate agreements are governed and evidenced separately; the platform does not claim government HIPAA certification.
SOC 2 program in preparation
Our control program is documented and operating. No observation period has opened yet. Scope: Security, Availability and Confidentiality. Processing Integrity and Privacy are deliberately out of scope; HIPAA governs the same data more strictly than the SOC 2 Privacy criteria would.
Public and NDA evidence
Public materials include policies, subprocessors, service status and honest program standing. Detailed architecture, control evidence, agreement references, recovery evidence and independent-test reports are shared only after review and, where appropriate, under NDA.
To request reviewed trust materials, contact noah@ettacare.com.