Trust Center
Security isn't a feature. It's the architecture.
Healthcare data demands more than checkbox compliance. We built Residora from the ground up with security and privacy as foundational constraints—not afterthoughts bolted on for sales decks.
Certifications & Compliance
Independent verification that we do what we say we do.
HIPAA
compliantFull compliance with Health Insurance Portability and Accountability Act
BAA available for all customers. Annual third-party audits.
SOC 2 Type II
certifiedService Organization Control 2 certification for security, availability, and confidentiality
Report available under NDA for enterprise customers.
GDPR
compliantGeneral Data Protection Regulation compliance for EU/UK operations
Data Processing Agreement available. EU data residency options.
Privacy Act (AU)
compliantAustralian Privacy Principles compliance
Australian data residency available for AU customers.
Security Architecture
Defense in depth. Multiple layers, no single points of failure.
Zero-Trust Architecture
Every request is authenticated and authorized. No implicit trust based on network location.
- mTLS for all internal service communication
- JWT tokens with short expiration
- IP allowlisting available for enterprise
- Session management with automatic timeout
Row-Level Security
Data access controlled to the individual record level. Users only see what they should.
- Database-enforced access policies
- Role-based access control (RBAC)
- Attribute-based access control (ABAC)
- Audit logging of all data access
Encryption Everywhere
Data encrypted at rest and in transit. No exceptions.
- AES-256 encryption at rest
- TLS 1.3 for all connections
- Customer-managed encryption keys (enterprise)
- Hardware security modules for key storage
Immutable Audit Trails
Every action timestamped and tamper-proof. Nothing gets deleted or modified.
- Append-only audit log architecture
- Cryptographic hash chain for integrity
- Minimum 7-year retention
- Export available for compliance reviews
Deterministic AI, Not Generative Hallucination
Our clinical AI uses rules and evidence—not probabilistic generation that makes things up.
No hallucinations
AI suggestions are derived from structured data and clinical rules, not generated text that might be wrong.
Clinician oversight
Every AI-assisted note requires human review and approval before signing. AI assists, you decide.
Transparent reasoning
When AI makes a suggestion, you can see why. No black-box decisions affecting patient care.
Regulatory alignment
Our AI approach is designed to meet emerging FDA guidance on clinical decision support.
Your Data, Your Questions
Straight answers to the questions security teams ask.
Where is my data stored?
US customers: AWS us-east-1 and us-west-2. UK/EU customers: AWS eu-west-2. Australian customers: AWS ap-southeast-2. Your data never leaves your designated region.
Who can access my data?
Your authorized users only. Residora staff cannot access customer data without explicit permission during support sessions, which are logged and time-limited.
How long is data retained?
You control retention policies within regulatory minimums. Audit logs retained 7 years minimum. All deletions are soft-deletes with recovery available.
What happens if I leave Residora?
Full data export in standard formats (CSV, JSON, FHIR). We provide 90 days to export after contract end. Your data is then securely destroyed with certificate provided.
Is my data used to train AI?
Never. Your clinical data is never used to train machine learning models. Our AI improvements come from anonymized, aggregated operational patterns only—and you can opt out of even that.
When Things Go Wrong
We hope we never need this. But you should know we have it.
Detection
< 15 min
Automated monitoring detects anomalies and alerts security team
Containment
< 1 hr
Affected systems isolated, access revoked, forensics begins
Notification
< 24 hrs
Affected customers notified per regulatory requirements
Resolution
Varies
Root cause analysis, remediation, and prevention measures
Questions? Let's talk security.
Our security team is available to discuss your specific compliance requirements and answer technical questions.