Every artifact below carries an honest status. Public artifacts are linked directly. NDA-gated artifacts are clearly labeled and available on request to trust@jetpatient.com. We don't sell trust badges we haven't earned, and we don't hide certifications behind a sales call.
Color-coded for honesty. Green = audited and reportable. Amber = audit underway with a fixed target. Gray = on the roadmap, not yet started.
JetPatient executes a HIPAA Business Associate Agreement with every covered entity, every TPA partner, and every sub-processor before any data exchange. PHI is encrypted with TLS 1.3 in transit and AES-256 at rest. Audit logs retained 7 years.
Engaged with Schellman as our independent auditor. Observation window: 2026-01-01 through 2026-09-30. First Type II report targeted Q4 2026. SOC 2 Type I is available under NDA today.
Gap assessment scheduled for Q3 2026 with a HITRUST-authorized External Assessor. r2 certification targeted Q2 2027 once SOC 2 Type II is reportable.
Full Administrative, Physical, and Technical safeguards implemented. Risk Analysis (§164.308(a)(1)) refreshed quarterly. Encryption-at-rest and -in-transit, audit controls, access controls, and integrity controls independently attested.
On the 2027 roadmap. Triggered by international expansion timeline (EU + UK self-funded scheme onboarding). Stage 1 audit targeted Q2 2027.
PREDICT classified high-risk under Annex III §5(a). Conformity assessment file maintained covering risk management (Art. 9), data governance (Art. 10), technical docs (Art. 11), record-keeping (Art. 12), transparency (Art. 13), human oversight (Art. 14), accuracy (Art. 15).
No NDA, no sales call, no email required. Each link is a real file.
Standard enterprise practice. Mutual NDA in two business days, document delivered same day after countersignature.
The full sub-processor list. BAA executed with each before any data exchange. New sub-processors notified 30 days in advance per our standard BAA addendum.
The metrics our on-call team is measured against. Pen-test cadence, tabletop cadence, and notification SLAs all formalized in the MSA.
Each function has a dedicated address with a documented SLA. No security questionnaire enters a sales inbox.