Trust & Security

Built for healthcare
privacy and security

CredVault protects credential data with encryption, access controls, audit logging, and enterprise-grade infrastructure.

Security posture

Every layer of CredVault is designed with defense in depth.

SOC 2 & Compliance

Our infrastructure is hosted on AWS (SOC 2 Type II, HIPAA-eligible). Credential data is encrypted at rest (AES-256) and in transit (TLS 1.2+).

Encryption

All data in transit is protected by TLS 1.2+ with strong cipher suites. Data at rest is encrypted using AES-256. Access to sensitive provider identifiers, including SSN and date of birth, is restricted by role-based access controls and logged to an append-only audit trail.

Access Controls

Every API request is authenticated via JWT with per-user token versioning. Role-based access (member, owner, admin) controls what each user can view or modify. All access is logged to an append-only audit trail.

Audit Logging

All credential changes, provider modifications, and administrative actions are recorded with timestamp, user ID, action type, and resource identifier.

Infrastructure

Hosted on AWS EC2 in the US. Backend runs on isolated containers with health checks and automated restarts.

Data Deletion

Account deletion removes all provider and credential data. Exports are available on request before deletion.

HIPAA & Business Associate Agreements

Clear answers about compliance, BAAs, and data handling.

Does CredVault sign Business Associate Agreements?
BAAs are available on request for covered entities and business associates that require one. Do not upload patient records or PHI unless a BAA is fully executed. Email hello@sycana.com to request a BAA.
How does CredVault approach HIPAA and healthcare privacy?
CredVault is built for healthcare practices with encrypted storage, access controls, and audit logging. The platform is intended for provider credential metadata, not patient records. BAAs are available on request for organizations that require one.
What data should we NOT upload?
Do not upload patient health records, clinical notes, treatment records, or payer files containing patient PHI. CredVault supports provider credential metadata and selected provider identifiers; sensitive provider fields are access-controlled and audit-logged, and should be used only when operationally necessary.
Where is our data stored?
CredVault application data is stored on AWS in the United States. Uploaded files are processed by an AI document parsing service for credential extraction. Do not upload patient records, clinical notes, or other patient PHI.
How long do you keep our data?
Account data is retained while your account is active. Deletion requests remove all provider and credential data. Exports are available on request before deletion. Backup copies are retained only as long as required by operational necessity.
How do team permissions work?
Practice owners can invite team members and assign role-based access for day-to-day credential work. Access is authenticated, scoped by role, and recorded in audit logs.
Can we export our data before cancellation or deletion?
Yes. CSV exports are available for credential reports and provider review. Request any needed exports before account deletion because deletion removes provider and credential data.
What happens if we cancel?
You retain access until the end of your billing period. After that, your data is held temporarily before deletion. You can request a full export at any time.

Subprocessors

Third-party subprocessors used to operate CredVault.

SubprocessorPurposeData location
AWS EC2Cloud infrastructure & hostingUnited States
AWS S3Document/file storageUnited States
ResendTransactional email deliveryUnited States
TwilioSMS notification deliveryUnited States
StripeBilling & payment processingUnited States
AI Document ParsingAI-powered data extraction from uploaded filesUnited States (cached)
JWT/SessionsAuthentication tokens — no third-party auth providerN/A (self-managed)

Have compliance questions?

We're happy to share security documentation, review vendor assessments, or start the BAA process.

Contact our security team