Trust Center · Public artifacts + NDA-gated artifacts

Honest about what's certified, honest about what's in progress.

Every artifact below carries an honest status. Public artifacts are linked directly. NDA-gated artifacts are clearly labeled and available on request to trust@jetpatient.com. We don't sell trust badges we haven't earned, and we don't hide certifications behind a sales call.

Last updated 2026-06-03 · Reviewed quarterly by the JetPatient Security & Compliance team
Status board

Where every certification stands today

Color-coded for honesty. Green = audited and reportable. Amber = audit underway with a fixed target. Gray = on the roadmap, not yet started.

Certified

HIPAA · BAA program

JetPatient executes a HIPAA Business Associate Agreement with every covered entity, every TPA partner, and every sub-processor before any data exchange. PHI is encrypted with TLS 1.3 in transit and AES-256 at rest. Audit logs retained 7 years.

Status: Standing program · BAA template downloadable below
In progress

SOC 2 Type II

Engaged with Schellman as our independent auditor. Observation window: 2026-01-01 through 2026-09-30. First Type II report targeted Q4 2026. SOC 2 Type I is available under NDA today.

Window: 9 mo · Report target: 2026 Q4
In progress

HITRUST CSF · gap assessment

Gap assessment scheduled for Q3 2026 with a HITRUST-authorized External Assessor. r2 certification targeted Q2 2027 once SOC 2 Type II is reportable.

Gap assessment: 2026 Q3 · Cert target: 2027 Q2
Certified

HIPAA Security Rule

Full Administrative, Physical, and Technical safeguards implemented. Risk Analysis (§164.308(a)(1)) refreshed quarterly. Encryption-at-rest and -in-transit, audit controls, access controls, and integrity controls independently attested.

Last risk-analysis refresh: 2026-04-05
Planned

ISO 27001 / 27701

On the 2027 roadmap. Triggered by international expansion timeline (EU + UK self-funded scheme onboarding). Stage 1 audit targeted Q2 2027.

Status: Roadmap · 2027 Q2
Conformity file

EU AI Act readiness

PREDICT classified high-risk under Annex III §5(a). Conformity assessment file maintained covering risk management (Art. 9), data governance (Art. 10), technical docs (Art. 11), record-keeping (Art. 12), transparency (Art. 13), human oversight (Art. 14), accuracy (Art. 15).

Last review: 2026-05-12 · Public summary: Compliance Attestation
Public artifacts · Download directly

The documents your security team can grab today

No NDA, no sales call, no email required. Each link is a real file.

Under NDA · Email trust@jetpatient.com

Documents we share, under simple mutual NDA

Standard enterprise practice. Mutual NDA in two business days, document delivered same day after countersignature.

BAA template (HIPAA Business Associate Agreement)
JetPatient's standard BAA. Reviewable by your counsel; redlines welcomed.
Request via NDA
SOC 2 Type I report (current period)
Schellman-issued Type I covering 2025-07 through 2025-12. Type II in progress, target Q4 2026.
Request via NDA
Security whitepaper
Full security architecture, threat model, control mapping, key management, data residency.
Request via NDA
Most recent penetration-test summary
Third-party penetration test completed 2026-03-08. Summary letter and remediation log available.
Request via NDA
Incident-response runbook
Severity definitions, escalation matrix, communications policy, post-incident review template.
Request via NDA
Standard security questionnaire (SIG / CAIQ)
Pre-completed SIG Lite, SIG Core, and CAIQ v4.0.3 questionnaires. Cuts your team's intake to a 10-minute review.
Request via NDA
Sub-processors

Every vendor that touches plan data

The full sub-processor list. BAA executed with each before any data exchange. New sub-processors notified 30 days in advance per our standard BAA addendum.

Sub-processor
Function
Region
Independent audit
AWS
Compute, storage, networking, KMS
us-east-1, us-west-2
SOC 2 · ISO 27001 · HITRUST
Snowflake
Data warehouse · cohort analytics
us-east, us-west
SOC 2 · HITRUST
Databricks
PREDICT model training pipeline
us-east
SOC 2 · ISO 27001
Auth0 (Okta)
SSO · SAML · MFA · SCIM broker
us
SOC 2 · ISO 27001
Datadog
Observability · audit log retention
us1
SOC 2
SendGrid (Twilio)
Transactional email
us
SOC 2
Twilio Programmable SMS
Member outreach SMS
us
SOC 2
Schellman
SOC 2 audit (independent)
us
AICPA-licensed
Incident response

How we behave when something goes wrong

The metrics our on-call team is measured against. Pen-test cadence, tabletop cadence, and notification SLAs all formalized in the MSA.

24×7
On-call coverage
Two-tier escalation · documented runbook
<15min
Sev-1 ack target
Acknowledged via status page + named-contact email
<24h
PHI incident notification
Well inside HIPAA's 60-day window
Q1·Q3
Tabletop cadence
Most recent 2026-03-08 · next 2026-09-12
Contact

Talk to the right inbox

Each function has a dedicated address with a documented SLA. No security questionnaire enters a sales inbox.

Trust & compliance

trust@jetpatient.com

Questionnaires, BAA, NDA, audit packs

Security (24×7)

security@jetpatient.com

Suspected incidents, vulnerabilities, PGP key on request

Integrations

integrations@jetpatient.com

EDI · FHIR · OAuth setup, sandbox keys, runbook