Trust Center

Security isn't a feature. It's the architecture.

Healthcare data demands more than checkbox compliance. We built Residora from the ground up with security and privacy as foundational constraints—not afterthoughts bolted on for sales decks.

HIPAA
SOC 2 Type II
GDPR
Privacy Act (AU)

Certifications & Compliance

Independent verification that we do what we say we do.

HIPAA

compliant

Full compliance with Health Insurance Portability and Accountability Act

BAA available for all customers. Annual third-party audits.

SOC 2 Type II

certified

Service Organization Control 2 certification for security, availability, and confidentiality

Report available under NDA for enterprise customers.

GDPR

compliant

General Data Protection Regulation compliance for EU/UK operations

Data Processing Agreement available. EU data residency options.

Privacy Act (AU)

compliant

Australian Privacy Principles compliance

Australian data residency available for AU customers.

Security Architecture

Defense in depth. Multiple layers, no single points of failure.

Zero-Trust Architecture

Every request is authenticated and authorized. No implicit trust based on network location.

  • mTLS for all internal service communication
  • JWT tokens with short expiration
  • IP allowlisting available for enterprise
  • Session management with automatic timeout

Row-Level Security

Data access controlled to the individual record level. Users only see what they should.

  • Database-enforced access policies
  • Role-based access control (RBAC)
  • Attribute-based access control (ABAC)
  • Audit logging of all data access

Encryption Everywhere

Data encrypted at rest and in transit. No exceptions.

  • AES-256 encryption at rest
  • TLS 1.3 for all connections
  • Customer-managed encryption keys (enterprise)
  • Hardware security modules for key storage

Immutable Audit Trails

Every action timestamped and tamper-proof. Nothing gets deleted or modified.

  • Append-only audit log architecture
  • Cryptographic hash chain for integrity
  • Minimum 7-year retention
  • Export available for compliance reviews

Deterministic AI, Not Generative Hallucination

Our clinical AI uses rules and evidence—not probabilistic generation that makes things up.

No hallucinations

AI suggestions are derived from structured data and clinical rules, not generated text that might be wrong.

Clinician oversight

Every AI-assisted note requires human review and approval before signing. AI assists, you decide.

Transparent reasoning

When AI makes a suggestion, you can see why. No black-box decisions affecting patient care.

Regulatory alignment

Our AI approach is designed to meet emerging FDA guidance on clinical decision support.

Generative AI
Residora
Source of suggestions
Generative AI (may hallucinate)
Deterministic rules + structured data
Clinical accuracy
Variable, requires verification
Consistent, rule-based logic
Audit trail
Often missing
Complete chain of reasoning
Human oversight
Optional
Required for all clinical decisions

Your Data, Your Questions

Straight answers to the questions security teams ask.

Where is my data stored?

US customers: AWS us-east-1 and us-west-2. UK/EU customers: AWS eu-west-2. Australian customers: AWS ap-southeast-2. Your data never leaves your designated region.

Who can access my data?

Your authorized users only. Residora staff cannot access customer data without explicit permission during support sessions, which are logged and time-limited.

How long is data retained?

You control retention policies within regulatory minimums. Audit logs retained 7 years minimum. All deletions are soft-deletes with recovery available.

What happens if I leave Residora?

Full data export in standard formats (CSV, JSON, FHIR). We provide 90 days to export after contract end. Your data is then securely destroyed with certificate provided.

Is my data used to train AI?

Never. Your clinical data is never used to train machine learning models. Our AI improvements come from anonymized, aggregated operational patterns only—and you can opt out of even that.

When Things Go Wrong

We hope we never need this. But you should know we have it.

Step 1

Detection

< 15 min

Automated monitoring detects anomalies and alerts security team

Step 2

Containment

< 1 hr

Affected systems isolated, access revoked, forensics begins

Step 3

Notification

< 24 hrs

Affected customers notified per regulatory requirements

Step 4

Resolution

Varies

Root cause analysis, remediation, and prevention measures

Questions? Let's talk security.

Our security team is available to discuss your specific compliance requirements and answer technical questions.