Trust Center
Everything your security
reviewer will ask for.
Medera holds PHI from live therapy sessions, so this page sets out the certifications we hold, the safeguards behind them, and how your security team can request the evidence for each one.
Certifications and frameworks
Reports, certificates and agreements are provided to customers and to prospects in an active evaluation, under NDA where required. Use the request link on each, or send your questionnaire to hi@medera.info.
SOC 2 Type II
Independently audited by an AICPA-accredited firm against the Security, Availability, Processing Integrity, Confidentiality and Privacy Trust Services Criteria, over a continuous observation period.
Request the SOC 2 Type II reportHIPAA
Administrative, physical and technical safeguards implemented across the platform, with a Business Associate Agreement executed with every covered entity before any PHI moves.
Request the HIPAA Security Rule mapping and BAACyber Essentials Plus
Certified under the UK government-backed scheme at the Plus level, which requires hands-on technical verification by an external assessor.
Request the Cyber Essentials Plus certificateGDPR
Data Processing Agreement with standard contractual clauses, full data subject rights support, and EU data-residency options for European deployments.
Request the Data Processing AgreementHIPAA and the Business Associate Agreement
Medera acts as a Business Associate. Every engagement begins with a signed BAA, executed before a single record moves, which settles lawful use, disclosure and safeguarding obligations for PHI in writing rather than by assurance.
What the safeguards actually are
- Administrative. Designated Privacy and Security Officers, workforce HIPAA training at hire and annually, a documented risk analysis reviewed at least yearly, background checks for anyone with PHI access, and a formal sanctions policy.
- Technical. Unique user identification, audit controls on every PHI access, automatic session termination, break-the-glass emergency access with post-access review, and integrity controls that detect unauthorised alteration.
- Physical. Primary infrastructure in US-based, HIPAA-eligible data centres operated under their own SOC 2 Type II attestation.
- Audit retention. Logs retained for a minimum of six years, as HIPAA requires.
SOC 2 Type II
Medera holds a SOC 2 Type II report, issued by an independent AICPA-accredited firm and scoped to Security, Availability, Processing Integrity, Confidentiality and Privacy. A Type II report examines whether controls operated effectively across a continuous observation window, which is the version that tells you something; a Type I is a snapshot.
The report is available to customers and to prospects in an active evaluation, under NDA. Request it through your account contact or at hi@medera.info.
Cyber Essentials Plus
We hold Cyber Essentials Plus, the UK government-backed scheme at its verified tier. Unlike the base level, Plus requires an external assessor to test the controls hands-on rather than accept a self-assessment. Certificate and assessment date are available on request, and the scheme maintains a public registry your team can check independently.
GDPR and international transfers
We offer a Data Processing Agreement incorporating standard contractual clauses, and we support the data subject rights the regulation grants: access, rectification, erasure subject to clinical retention obligations, restriction, portability and objection. Verified requests are answered within thirty days, or sooner where local law requires.
EU data-residency options are available for European deployments. Raise residency requirements during evaluation and we will confirm the deployment region in writing before you contract.
Security architecture
- Encryption in transit. TLS 1.2 or above on every connection, with modern cipher suites only.
- Encryption at rest. AES-256-GCM, with HSM-backed key management and automated 90-day key rotation.
- Access control. Least privilege by default, role-based permissions, mandatory MFA for all workforce access, and no standing production access.
- Tenant isolation. Customer data is logically separated, and every query path is scoped to a single organisation.
- Audit trail. Every agent action and every PHI access writes an immutable log entry carrying user identity, timestamp, action, data elements touched and source IP.
- Testing. Continuous third-party penetration testing, with findings tracked to closure.
Data handling, retention and deletion
You own your clinical data. We process it to deliver the service and for nothing else.
- Residency. Primary processing and storage in United States regions.
- Session audio. Retained only as long as needed to produce and confirm the documentation, then deleted on the schedule your organisation sets.
- Retention. Configurable per organisation within the limits clinical record-keeping law imposes.
- Deletion and export. On termination, a full export in a machine-readable format, then deletion within the contracted window, backups included.
AI, models and training data
This is the section most trust pages skip, and the one that matters most for a product that sits inside therapy sessions.
- Your data does not train foundation models. Customer PHI is never used to train, fine-tune or evaluate any general-purpose model, ours or a vendor's. This is contractual, not a setting.
- A clinician approves every output. No note is filed, no code is submitted and no message is sent without a human signing it. The approval gate is architectural: there is no configuration that removes it.
- Answers carry their sources. Clinical guidance surfaced in-session cites what it drew on, so a clinician can judge it rather than trust it.
- Agents act inside a defined scope. Each agent owns a narrow, auditable job and cannot act outside it. What each one does, and what it will never do unattended, is documented.
- Medera assists; it does not diagnose. The system is a clinical support tool and is not a medical device, not a diagnostic instrument, and not a substitute for clinical judgment.
Subprocessors
Published rather than gated, because every security review asks for it on day one. Each is bound by a written agreement no less protective than our own commitments, with HIPAA flow-down provisions where PHI is involved. Covered entities receive thirty days' written notice before we engage a new subprocessor that will process their PHI, with the right to object.
| Purpose | Data involved | Commitments |
|---|---|---|
| Cloud infrastructure & hosting | All application data and PHI, encrypted at rest and in transit | US regions only · HIPAA-eligible services · SOC 2 Type II · BAA in place |
| Transactional email | Names and email addresses. No PHI in message bodies. | BAA in place · no message content retained beyond delivery logs |
| Payment processing | Billing contact and payment method. No clinical data. | PCI DSS Level 1 · card data never touches Medera systems |
| Application performance monitoring | De-identified telemetry, error traces and latency metrics | PHI scrubbed before egress · no request bodies captured |
| Customer support platform | Support correspondence and account metadata | BAA in place · PHI access controls · no bulk export |
Named vendors for each row are listed in the security packet. To be notified when this list changes, email hi@medera.info.
Incident response and disclosure
- Notification. Affected Covered Entities are notified without unreasonable delay and within the timeline the BAA and the HIPAA Breach Notification Rule require.
- What you get. What happened, what data was involved, what we have done, and what we are changing so it does not recur.
- Reporting a vulnerability. Send it to hi@medera.info. We acknowledge within one business day and will not pursue legal action against good-faith research that respects patient privacy and avoids service disruption.
Security reviews are welcome
Send us your questionnaire. We answer them properly rather than deflecting to a portal, and enterprise customers may audit our compliance with the BAA and these commitments once in any twelve-month period, more often following an incident, on thirty days' notice.
The security packet contains the SOC 2 Type II report, the Cyber Essentials Plus certificate, our HIPAA Security Rule mapping, the named subprocessor list, our architecture overview and the most recent penetration test summary.
Who to contact
- Security and privacy. hi@medera.info
- Data subject requests. Same address. Verified requests answered within thirty days.
- Contracting entity. Medera, Inc., a Delaware corporation. Medera Health is our patient-facing care-coordination service and operates under the same entity.
Related: our Privacy Policy, Terms of Service, SMS programme and clinical safety commitments.
Send us your security questionnaire.
We would rather answer it now than at implementation.