Trust Center

Security, privacy, and auditability—transparent by design.

Vitruviana is built for healthcare operations with evidence-first workflows, audit logging, and BAA-ready deployments.

Data flow & environments

Separate demo vs production data. Production environments support HIPAA-aligned controls and audit logging.

Access controls

Role-based access, MFA support, audit trails, and break-glass procedures for sensitive workflows.

Retention & deletion

HIPAA documentation retained for at least 6 years. Clinical record retention follows state requirements.

Subprocessors

Public list of infrastructure and AI subprocessors with data handling summaries.

BAA availability

Business Associate Agreements available on request for production deployments.

Incident response

Documented incident response plan, notification workflow, and security monitoring.

Request security packet

Get architecture diagrams, subprocessors list, audit controls, and BAA request steps.