Trust center

A plain statement of the safeguards and assurance evidence EttaCare can support today.

Security practices

EttaCare uses encryption in transit and at rest, role- and relationship-based access controls, append-only audit evidence, malware scanning, private networking and tested fail-closed production configuration. No seal or technical control eliminates all risk.

Health-care privacy

EttaCare supports practices operating under HIPAA and state health-care privacy requirements. Practice and vendor business associate agreements are governed and evidenced separately; the platform does not claim government HIPAA certification.

SOC 2 program in preparation

Our control program is documented and operating. No observation period has opened yet. Scope: Security, Availability and Confidentiality. Processing Integrity and Privacy are deliberately out of scope; HIPAA governs the same data more strictly than the SOC 2 Privacy criteria would.

Public and NDA evidence

Public materials include policies, subprocessors, service status and honest program standing. Detailed architecture, control evidence, agreement references, recovery evidence and independent-test reports are shared only after review and, where appropriate, under NDA.

To request reviewed trust materials, contact noah@ettacare.com.