Trust & security
Built for healthcare data from day one
Embed Care owns the patient record, so security is our responsibility — not a vendor’s afterthought. Here’s how we protect it.
Encryption everywhere
TLS 1.2+ in transit, AES-256 at rest. Secrets in a managed vault, never in code.
Tenant isolation
Postgres row-level security keys every record to its tenant — isolation is a database invariant, not a query convention.
Least privilege + MFA
Role-based access (admin / partner / clinician / patient), MFA on internal access, scoped API keys per tenant.
Audit everything
Every access to a record is logged with who, what, and when — available to partners and exportable.
Subprocessors
The services that process data on our behalf — each under a BAA where PHI is involved.
| Service | Role | BAA |
|---|---|---|
| Supabase / Postgres | Primary datastore + RLS | Yes |
| Twilio | SMS / voice | Yes |
| SendGrid | Transactional email | Yes |
| Stripe | Payments + payouts | N/A (no PHI) |
| Pharmacy / EMR adapters | Fulfillment + records | Per partner |
Security program
The controls below operate in production today; the attestations beneath them are being formalized.
Operating today
- Security Risk Assessment
- BAAs with every subprocessor
- Tenant isolation + audit logging in production
Attestations underway
- 1Third-party penetration test
- 2SOC 2 Type II
Need our security package or a BAA for diligence? We’ll walk your team through it.
This page describes the production security posture. The interactive demo uses synthetic data only — no PHI.
Ready to make this your brand?
Plug in your audience. We run the clinic. You keep the revenue.