Security & trust

Your residents' data, protected like the company depends on it.Because it does.

CareDocs.ai is HIPAA compliant and SOC 2 attested, built on Microsoft Azure. Security decisions were made when the architecture was drawn, not after — and we'll show your reviewers exactly how.

HIPAA compliant

Every customer relationship begins with a Business Associate Agreement, and every workflow — including the AI — handles resident information under HIPAA’s minimum-necessary principle. Privacy is how the platform works, not a setting.

SOC 2 attested

An independent auditor has attested our security controls under SOC 2. Those same controls run in production every day, continuously monitored — not assembled once a year for audit season.

Built on Microsoft Azure

CareDocs.ai runs entirely on HIPAA-eligible Microsoft Azure services, AI included, with identity managed through Microsoft Entra. Your data lives behind the enterprise-grade protections regulated healthcare already trusts.

Encrypted, always

Resident data is encrypted in transit and at rest, without exception. Encryption is the default state of your data — never an option someone has to remember to turn on.

Isolated by architecture

Each facility’s data is partitioned at the database level, and every query runs inside its own partition. Isolation is enforced by the architecture itself — not left to policy.

Everything on the record

Every clinically or financially significant action is logged — who did what, when, and to which record. When a surveyor or reviewer asks, the answer is already written down.

AI you can hold accountable

Every AI-assisted output can be traced back to the request and the data behind it, and reviewed. Your facility’s data is never used to train foundation models.

Secure by practice

Every change to our software passes automated security analysis before it ships. Protecting resident data is an engineering discipline here, not a compliance exercise.

Security review coming up?

Put us in front of your security reviewers: the BAA, the SOC 2 report, an architecture overview, and an engineer on the call.

Request the trust package
FAQ

Security questions, answered

Will CareDocs.ai sign a Business Associate Agreement (BAA)?

Yes. A BAA is part of every customer relationship — including AI processing, which runs on HIPAA-eligible Azure services under the same agreement.

Where is our data stored?

In Microsoft Azure data centers in the United States, encrypted at rest and in transit. Each facility’s data is isolated at the database level.

Is protected health information used to train AI models?

No. AI features process your data to serve your facility — drafting, auditing, answering questions — and that data is not used to train foundation models.

How do you handle authentication?

Identity is managed through Microsoft Entra ID with modern authentication flows. Role-based access control governs every surface — physicians, therapists, assistants, billers, and administrators each see exactly what their role permits.

What happens when staff receive email notifications?

Notification emails are deliberately free of protected health information. They tell the recipient what needs attention and link into the authenticated product, where role-based access applies.

Can we review your security posture before buying?

Yes — request our trust package through the contact form and we’ll walk your security reviewers through architecture, controls, and attestations.

See it on your own workflows.

Bring a de-identified eval, schedule, or contract — most teams know within one demo.