Trust & security

Security & Trust

Last updated: 26 July 2026

InteliClaim handles protected health information, so security isn't a feature we bolted on. It's engineered to the bar hospital and enterprise procurement teams demand, and designed in from the first commit.

This page describes the controls built into the InteliClaim product. It is a summary, not a certification or a contract. We confirm our current compliance posture per engagement and can share a fuller trust package under NDA. Please don't submit PHI through this website.

Data protection

Your data is encrypted, isolated, and never used to train models.

  • AES-256 encryption in transit and at rest, with managed key rotation.
  • Strict tenant isolation at the application and database layer, per customer.
  • No model training on your charts. What's yours stays yours.
  • Least-privilege PHI handling throughout the platform.

Identity & access

Your directory stays the source of truth, with access scoped tightly.

  • MFA and single sign-on for staff access.
  • SCIM provisioning, so access is removed the moment someone leaves.
  • Role-based access with custom roles and per-user overrides.
  • Break-glass access, time-boxed, reason-required, and fully audited.

Monitoring & audit

Every action is recorded, and unusual access is caught early.

  • Immutable, append-only audit logs on every action.
  • PHI-access anomaly detection with alerting on unusual patterns.
  • Session controls, idle timeout and automatic logoff.
  • Exportable evidence for your compliance reviews.

AI safety & governance

The AI is explainable, guarded, and resilient, with people in control.

  • Evidence on every output, a confidence score and the source note behind it.
  • Human review by default, with autonomy you configure per clinic.
  • Prompt-injection protection, risky inputs routed to a person.
  • Multi-model failover, so one provider outage never stops the work.
  • Drift & quality monitoring on model behavior over time.

Infrastructure & supply chain

Hardened at the edges and transparent about what's inside.

  • Web application firewall and tiered rate limiting.
  • Signed (HMAC) webhooks for verified integration callbacks.
  • API-key rotation with grace periods, no hard cutovers.
  • Software bill of materials (SBOM) generated in our build pipeline.

Compliance posture

Where we are today, stated plainly.

  • HIPAA-aligned architecture, US healthcare regulation shaped the design.
  • SOC 2 readiness underway, with automated evidence collection. Not yet certified.
  • BAAs available for customers handling PHI.
  • Posture confirmed per engagement, tell us your requirements.

Need the full trust package?

Procurement, security, and legal teams can request our detailed trust overview with control mappings. Tell us your requirements and we'll walk you through how we meet them.

Request the trust overview

InteliClaim is a product of Norevia LLC · Bentonville, Arkansas, USA