Trust center

Built for the standards healthcare operates under.

Healthcare organizations can't adopt technology they can't trust. This page answers the questions your security, compliance, and IT teams ask first, in plain language and without the runaround.

Core controls

How we protect your data.

Encryption everywhere

Data is encrypted in transit and at rest across the platform.

Tenant isolation

Each customer's data and agents are isolated from every other tenant.

Least-privilege access

Integrations are scoped to exactly what a workflow needs. Secrets live in a managed vault, never in code.

Full audit logging

Every action ANDR3W takes is logged and reviewable, a complete, accountable trail.

US-hosted infrastructure

Built and operated on secure, US-region cloud infrastructure.

Human oversight

Approval gates and configurable guardrails keep people in control of consequential actions.

Your data

How we handle it.

The short version: your data is yours, it stays isolated, it is used only to do the work you direct, and it never trains our models.

We do not train or fine-tune models on your data.
Customer data is isolated per tenant and used only to perform the work you direct.
We minimize data by design: our focus is administrative and operational work that does not require clinical or patient data.
Where a deployment involves protected health information, processing is routed to BAA-covered infrastructure and model configurations.
Data is retained only as long as needed to provide the service and meet legal obligations, then deleted or archived on a defined schedule.
Compliance

A deliberate path, honestly stated.

We take compliance seriously enough to be precise about it. Here is where we are and where we are headed. No overstatement, because your risk team will check.

SOC 2 Type II examination underway
We are pursuing an independent SOC 2 Type II examination, the report enterprise buyers rely on to confirm controls operate over time.
HIPAA Security Rule alignment
The platform is designed around HIPAA administrative, technical, and physical safeguard requirements.
BAA where we are a business associate
Where a deployment would have ANDR3W handle protected health information, we do so only under a Business Associate Agreement and only as that agreement permits.
HITRUST on our roadmap
We are building toward the frameworks health systems ask for in vendor risk reviews, HITRUST included.

Subprocessors

We use a short, vetted set of enterprise infrastructure and AI-model providers to deliver the service, each under appropriate data-protection terms and, where applicable, a Business Associate Agreement. We maintain a current subprocessor list and provide notice of changes as set out in your agreement.

Incident response

We monitor continuously and maintain a defined process for detecting, investigating, and responding to security events, including timely notification consistent with your agreement and applicable law. Our providers are contractually obligated to notify us of security incidents so we can act quickly.

Bring your security team.

We are glad to walk your security, compliance, and IT stakeholders through our architecture and controls in detail, and to complete your vendor security review.