Built for healthcare
privacy and security
CredVault protects credential data with encryption, access controls, audit logging, and production-grade infrastructure.
Security posture
Every layer of CredVault is designed with defense in depth.
SOC 2 & Compliance
Our infrastructure is hosted on AWS (SOC 2 Type II, HIPAA-eligible). Credential data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
Encryption
All data in transit is protected by TLS 1.2+ with strong cipher suites. Data at rest is encrypted using AES-256. Access to sensitive provider identifiers, including SSN and date of birth, is restricted by role-based access controls and logged to an append-only audit trail.
Access Controls
Every API request is authenticated via JWT with per-user token versioning. Role-based access (member, coordinator, org admin, super admin) controls what each user can view or modify. All access is logged to an append-only audit trail.
Audit Logging
All credential changes, provider modifications, and administrative actions are recorded with timestamp, user ID, action type, and resource identifier.
Infrastructure
Hosted on AWS EC2 in the US. Backend runs on isolated containers with health checks and automated restarts.
Data Deletion
Account deletion removes all provider and credential data. Exports are available on request before deletion.
HIPAA & Business Associate Agreements
Clear answers about compliance, BAAs, and data handling.
Does CredVault sign Business Associate Agreements?
HIPAA & PHI handling: how is provider data protected?
How does CredVault approach HIPAA and healthcare privacy?
What data should we NOT upload?
Where is our data stored?
How long do you keep our data?
How do team permissions work?
Can we export our data before cancellation or deletion?
What happens if we cancel?
Subprocessors
Third-party subprocessors used to operate CredVault.
| Subprocessor | Purpose | Data location |
|---|---|---|
| AWS EC2 | Cloud infrastructure & hosting | United States |
| AWS S3 | Document/file storage | United States |
| Resend | Transactional email delivery | United States |
| Twilio | SMS notification delivery | United States |
| Stripe | Billing & payment processing | United States |
| DeepSeek | AI document parsing, chat assistant, and extraction | Processed outside the United States (China) |
| PostHog | Product analytics (usage events; no PHI) | United States |
| HelloSign (Dropbox Sign) | E-signatures for BAAs and documents | United States |
Before content is sent to the AI provider (DeepSeek), PII identifiers — including SSN, date of birth, phone number, email, and address — are scrubbed server-side so the AI never receives identifiable provider data.
Have compliance questions?
We're happy to share security documentation, review vendor assessments, or start the BAA process. BAA requests are handled through the platform's BAA management flow — email security@getcredvault.com to request one.
Contact our security team