Security & trust

Your residents' data, protected like the company depends on it.Because it does.

CareDocs.ai is HIPAA compliant and SOC 2 attested, built on Microsoft Azure. Security decisions were made when the architecture was drawn, not after — and we'll show your reviewers exactly how.

HIPAA compliant

Every customer relationship begins with a Business Associate Agreement, and every workflow, including the AI, handles resident information under HIPAA’s minimum-necessary principle. Privacy is how the platform works, not a setting.

SOC 2 attested

An independent auditor has attested our security controls under SOC 2. Those controls run in production every day, built into how the platform is engineered rather than stood up before an audit. Your reviewers can request the report.

Built on Microsoft Azure

CareDocs.ai runs entirely on HIPAA-eligible Microsoft Azure services, AI included, with identity managed through Microsoft Entra. Your data lives behind the same protections regulated healthcare already relies on.

Encrypted, always

Resident data is encrypted in transit and at rest, without exception. Encryption is the default state of your data, with no setting to configure.

Isolated by architecture

Each facility’s data is partitioned at the database level, and every query runs inside its own partition. Isolation is enforced by the architecture itself, not left to policy.

Everything on the record

Every clinically or financially significant action is logged: who did what, when, and to which record. When a surveyor or reviewer asks, the answer is already written down.

AI you can hold accountable

Every AI-assisted output can be traced back to the request and the data behind it, and reviewed. Your facility’s data is never used to train foundation models.

Secure by practice

Every change to our software passes automated security analysis before it ships. Protecting resident data is part of how the software is built, and it is checked on every change.

For your security review

The BAA, the SOC 2 report, an architecture overview, and an engineer on the call, ready whenever the review starts.

Request the trust package
FAQ

Security questions, answered

Will CareDocs.ai sign a Business Associate Agreement (BAA)?

Yes. A BAA is part of every customer relationship, including AI processing, which runs on HIPAA-eligible Azure services under the same agreement.

Where is our data stored?

In Microsoft Azure data centers in the United States, encrypted at rest and in transit. Each facility’s data is isolated at the database level.

Is protected health information used to train AI models?

No. AI features process your data to serve your facility: drafting, auditing, answering questions. That data is not used to train foundation models.

How do you handle authentication?

Identity is managed through Microsoft Entra ID with modern authentication flows. Role-based access control governs every surface. Physicians, therapists, assistants, billers, and administrators each see exactly what their role permits.

What happens when staff receive email notifications?

Notification emails are deliberately free of protected health information. They tell the recipient what needs attention and link into the authenticated product, where role-based access applies.

Can we review your security posture before buying?

Yes. Request our trust package through the contact form and we’ll walk your security reviewers through architecture, controls, and attestations.

Start today — without changing the tools you run.

No integration required: the audits begin the day you sign up. In the demo, bring a case you know well and we'll document the eval together, start to signature.