Healthcare AI vendors talk about security in vague terms. We do not. Drata continuously monitors 244 security and infrastructure controls across our systems, code, and personnel, and updates our public security posture every day. The same report we share with auditors is open to any prospective customer to inspect.
The strongest test of a vendor is not what they say about themselves. It is what they will commit to in writing. Here are the questions we recommend asking every vendor you evaluate, and our answers to each.
Drata connects directly to our infrastructure, version control, identity provider, endpoints, and HR systems. It continuously verifies that 244 controls are in place and functioning. The report you can open from this page is the same one we share with our SOC 2 auditors, updated automatically every day.
Open live report →The 244 controls in our report fall into ten broad categories. Each is monitored automatically every day. Specific control implementations are documented in policies available on request; the categories below show the scope of what is covered.
Compliance frameworks are not all equal. SOC 2 Type II is the most common baseline for security, availability, and confidentiality controls. HIPAA with a Business Associate Agreement is the law for any vendor that touches PHI. US data residency is the commitment that customer data is stored only inside the United States. We maintain all three.
In an industry where vendors increasingly store healthcare data in international cloud regions and rely on offshore service providers, we make a commitment that is contractually binding and continuously monitored: every chart we process is stored only inside the United States, and every person who can access PHI works inside it.
Our policies are documented, reviewed quarterly, and approved by our security steering committee. If you are evaluating us as a vendor and need to see a specific policy in writing, under NDA when appropriate. Most vendors decline. We do not.
Request a policy →