Skip to content
Trust

Built for regulated work. The trust posture has to match.

Healthcare and life-sciences buyers ask the same questions on the first call: where does my data live, do you train on it, can I audit what your system did, what can your AI do on its own, and what happens when something goes wrong. Here is how we answer them — plainly, and with the receipts to back each one.

Principles

What we will not compromise on — in effect today, not on a roadmap.

01

We do not train on your content.

Customer sources and queries are never used to train, fine-tune, or evaluate any model. Knowledge enters the certified substrate only when a qualified human approves it.

02

Your data stays in your region — including at inference.

Knowledge Assets and their sources are stored in the GCP region you nominate — EU customers default to an EU region, India customers to an India region. Models run within your GCP boundary; your sources and queries are not sent to external model providers. We follow your regulator before our convenience.

03

Agents act within bounds you can see.

Our agents build and maintain knowledge — they do not decide what is true. Every consequential action passes policy guardrails, and clinical, coverage, and regulatory outputs require a qualified human's sign-off before they take effect. What each agent may access and do is configured per deployment and written to the same audit log as everything else.

04

It cites, or it refuses.

Every answer traces to a certified clinical source. When there is no certified basis for an answer, the system declines rather than guessing — and the refusal is logged. In regulated work, a defensible “no” beats a confident guess.

05

Every action is logged, verifiably.

Queries, citations, refusals, builds, and version transitions are written to a hash-chained audit log. Anyone with access can verify the chain on demand — without taking our word for anything.

06

Tamper-evident builds.

Each certified Knowledge Asset is sealed with a SHA-256 build hash plus an independent transparency-log attestation. The version your AI used is the version you can reproduce in any audit, indefinitely.

07

Customer data isolation.

Each organisation's data is segregated at the storage and processing tier. Cross-tenant queries are not architecturally possible. PHI is de-identified where the workflow allows.

08

Run it in your environment.

Beyond our managed cloud, Healthattica can deploy inside your own GCP organisation with VPC Service Controls, or fully self-hosted — so your sources and PHI never leave your perimeter.

Compliance posture

Where the paperwork stands today.

We are in early access. Some items are in progress and we say so plainly. If a certification is on the roadmap rather than in hand, this page will say that until it changes.

HIPAABAA available for US healthcare engagements
Available
21 CFR Part 11Designed to support electronic-records & audit-trail requirements; CSV documentation for GxP engagements
Supported by design
GDPR / UK GDPRDPA available on request
DPA available
EU data residencyDefault for EU customers
Default
India data residencyDefault for India customers
Default
PHI de-identificationAvailable within supported workflows
Available
SOC 2 Type IIReport available on request
In progress
ISO 27001Certification planned
On roadmap
HITRUSTCertification planned
On roadmap
BYOK — customer-managed keysScheduled for general availability; today, at-rest encryption uses GCP-managed keys and tenant separation is the durable control
On roadmap
Sub-processorsList published on request
Published on request
Incident responseNotification to your named contact within 24 hours
24h notification

How to reach us

Three inboxes, one promise — each monitored by the team that owns the question. No tickets bounce between functions.

General
hello@healthattica.com

Security brief, DPA, BAA, commercial, partnership, press.

Privacy
privacy@healthattica.com

GDPR / UK GDPR data-subject requests, DPA enquiries, sub-processor list. Response within 30 days.

Security
security@healthattica.com

Vulnerability reports, incident contacts, coordinated disclosure. Acknowledged within two working days. Details at /.well-known/security.txt.