Trust & Security

Built for healthcare
privacy and security

CredVault protects credential data with encryption, access controls, audit logging, and production-grade infrastructure.

Security posture

Every layer of CredVault is designed with defense in depth.

SOC 2 & Compliance

Our infrastructure is hosted on AWS (SOC 2 Type II, HIPAA-eligible). Credential data is encrypted at rest (AES-256) and in transit (TLS 1.2+).

Encryption

All data in transit is protected by TLS 1.2+ with strong cipher suites. Data at rest is encrypted using AES-256. Access to sensitive provider identifiers, including SSN and date of birth, is restricted by role-based access controls and logged to an append-only audit trail.

Access Controls

Every API request is authenticated via JWT with per-user token versioning. Role-based access (member, coordinator, org admin, super admin) controls what each user can view or modify. All access is logged to an append-only audit trail.

Audit Logging

All credential changes, provider modifications, and administrative actions are recorded with timestamp, user ID, action type, and resource identifier.

Infrastructure

Hosted on AWS EC2 in the US. Backend runs on isolated containers with health checks and automated restarts.

Data Deletion

Account deletion removes all provider and credential data. Exports are available on request before deletion.

HIPAA & Business Associate Agreements

Clear answers about compliance, BAAs, and data handling.

Does CredVault sign Business Associate Agreements?
BAAs are available on request for covered entities and business associates that require one. Do not upload patient records or PHI unless a BAA is fully executed. Email security@getcredvault.com to request a BAA.
HIPAA & PHI handling: how is provider data protected?
Sycana Health AI LLC (operating as CredVault) is ready to sign a Business Associate Agreement through the platform's BAA management flow. The platform is intended for provider credential metadata — patient health records and clinical notes must not be uploaded. Provider identifiers, including SSN, are access-controlled and audit-logged, and content sent for AI processing is anonymized server-side before transmission.
How does CredVault approach HIPAA and healthcare privacy?
CredVault is built for healthcare practices with encrypted storage, access controls, and audit logging. The platform is intended for provider credential metadata, not patient records. BAAs are available on request for organizations that require one.
What data should we NOT upload?
Do not upload patient health records, clinical notes, treatment records, or payer files containing patient PHI. CredVault supports provider credential metadata and selected provider identifiers; sensitive provider fields are access-controlled and audit-logged, and should be used only when operationally necessary.
Where is our data stored?
CredVault application data is stored on AWS in the United States. AI document parsing and chat assistant features are provided by DeepSeek, which processes data outside the United States; PII identifiers are scrubbed server-side before content is transmitted to the AI provider. Do not upload patient records, clinical notes, or other patient PHI.
How long do you keep our data?
Account data is retained while your account is active. Deletion requests remove all provider and credential data. Exports are available on request before deletion. Backup copies are retained only as long as required by operational necessity.
How do team permissions work?
Practice owners can invite team members and assign role-based access for day-to-day credential work. Access is authenticated, scoped by role, and recorded in audit logs.
Can we export our data before cancellation or deletion?
Yes. CSV exports are available for credential reports and provider review. Request any needed exports before account deletion because deletion removes provider and credential data.
What happens if we cancel?
You retain access until the end of your billing period. After that, your data is held temporarily before deletion. You can request a full export at any time.

Subprocessors

Third-party subprocessors used to operate CredVault.

SubprocessorPurposeData location
AWS EC2Cloud infrastructure & hostingUnited States
AWS S3Document/file storageUnited States
ResendTransactional email deliveryUnited States
TwilioSMS notification deliveryUnited States
StripeBilling & payment processingUnited States
DeepSeekAI document parsing, chat assistant, and extractionProcessed outside the United States (China)
PostHogProduct analytics (usage events; no PHI)United States
HelloSign (Dropbox Sign)E-signatures for BAAs and documentsUnited States

Before content is sent to the AI provider (DeepSeek), PII identifiers — including SSN, date of birth, phone number, email, and address — are scrubbed server-side so the AI never receives identifiable provider data.

Have compliance questions?

We're happy to share security documentation, review vendor assessments, or start the BAA process. BAA requests are handled through the platform's BAA management flow — email security@getcredvault.com to request one.

Contact our security team