Trust credo
This page shows our current security and compliance posture without inflated claims or borrowed cloud badges. Use it as your first pass, then request evidence and contract redlines.
- Stack: Next.js 16, Express 5, Temporal.
- Region: DigitalOcean NYC region.
- Runtime: Docker Compose integration baseline.
- Data policy: No model training on customer data.
Certifications, attestations, and the controls behind them
We are explicit about what is in force, what is roadmap, and what is inherited from our cloud provider. Nothing is asserted that is not yet true.
SOC 2 Type II
Program is planned. We do not represent active attestation yet.
HIPAA-eligible architecture
Architecture is designed toward HIPAA controls. A BAA path is on the roadmap — we don't assert a certification we don't yet hold.
ISO 27001
Cloud controls from DigitalOcean are part of infra posture, not product certification.
State AI Disclosure
State-specific language is versioned and enforced by scenario.
PHI production runtime
Production healthcare PHI remains blocked until BAA/ZDR/legal and customer signoff gates are complete.
Incident Response
Escalation runbooks, owner routing, and response timelines are defined.
Where humans decide, a human decides
Automated policy checks route risk; human review owns business and clinical accountability before risky access workflow actions proceed.
Policy checks
Human gates
Proof of work, not proof of talk
We publish measurable access workflow baselines and ship validation commands that any reviewer can run locally. The numbers below are targets and current baselines, not marketing projections.
Evidence checks
100%
Average page latency
<450ms
Retention baseline
7 years
Evidence signing
ed25519
docker compose up --build
pnpm lint
pnpm verify
pnpm --filter verigence-api build:openapi
pnpm --filter verigence-web gen:apiEvery vendor. What they touch. Where it lives.
Swipe or scroll sideways to review each vendor's role, data class, and region.
| System | Role | Data class | Region |
|---|---|---|---|
| Twilio | Gated future voice transport | No production PHI until contract gates | Per approved contract |
| OpenAI | Text LLM reasoning and transcription | PII / PHI only after contract gates | Per OpenAI enterprise terms |
| DigitalOcean Managed PostgreSQL | Structured event storage | PII / PHI when tenant-approved | NYC region |
| Clerk | Admin identity | Operator identity | US |
| DigitalOcean App Platform | Build and deployment automation | Source metadata | US |
If something goes wrong, we tell you fast
- Critical incidents acknowledged inside 1 hour.
- Initial containment update within 4 hours.
- Customer-facing summary and timeline with owner handoff.
HIPAA is not a certification program. Verigence has HIPAA-oriented architecture; a BAA path is on the roadmap. SOC 2 Type II remains roadmap until complete. Statements on this page reflect live posture, contract-bound controls, and roadmap items — no borrowed cloud badges.
What procurement usually asks us
Can we claim you are HIPAA certified?
No. HIPAA is not a certification program. We support HIPAA-aligned controls; a BAA path is on our roadmap and we do not yet operate under a BAA.
Do you have SOC 2 right now?
Not yet. SOC 2 Type II is in the roadmap and will be published after completion.
Can we get architecture evidence during review?
Yes. We provide architecture flow, control posture, and contract boundary walkthroughs during procurement.
Can we constrain to US-only data handling?
Structured storage is configured in a selected US region. The public demo uses a demo-safe voice path; ConversationRelay is an intended gated transport, not a production-PHI path today. Region and provider requirements are confirmed during procurement before production activation.