Skip to main content

Security and compliance

Encore OS is pre-production. It is designed toward HIPAA and 42 CFR Part 2 safeguards and designed toward SOC 2 Type II controls. It holds no certification, and no audit report exists yet.

Where Encore OS stands on each regime

  • HIPAA Security Rule: designed toward its administrative, physical and technical safeguards.
  • 42 CFR Part 2: designed toward the 2024 final rule. The database checks below enforce parts of it today.
  • Designed toward SOC 2 Type II controls. There is no audit report yet, and this site claims no attestation.

42 CFR Part 2, enforced in the database

Substance-use records stay protected when data is copied, derived or reported on.

Embedding analytics that could include Part 2 data needs a standing authorization, and the check fails closed.

A report cannot be grouped by a substance-use attribute.

The care-gap check answers with yes-or-no flags and never returns the record itself.

Data derived from a Part 2 chart carries a flag that an update can add but never remove.

These checks are in the product's database schema today. Consent capture is in build.

  • pf_analytics_org_part2_embed_authorized()
  • pf_analytics_run()
  • cl_care_gap_part2_gate()
  • is_part2_derived
  • In build42 CFR Part 2 consent capture with redisclosure tracking

Each organization sees only its own data

Every row in the product database belongs to one organization, and row-level security in the database limits each person to the organizations they are a member of.

Permissions are role-based on top of that, and staff sign-in can go through Microsoft Entra ID.

Role-based permissions are in build. Sign-in with Microsoft Entra ID is in build.

  • In buildRole-based permissions, including access rules for each object type
  • In buildStaff sign-in with Microsoft Entra ID

AI runs only after a published disclosure

AI note drafting will not run until the organization publishes a disclosure for the model.

Before any model call, the drafting function looks for a published disclosure for that exact model and version. With no published disclosure, or on any error, it drafts nothing. A patient can opt out, and the clinician reviews and attests to every AI-drafted note before signing it.

AI note drafting is in build.

  • cl_dsi_disclosures
  • cl-ai-generate-draft
  • In buildAI-drafted progress notes that the clinician reviews and attests to before signing

What this page does not claim

  • No certification or audit report.
  • No uptime or availability figures.
  • No customers. No organization runs Encore OS in production yet.

Questions

Send security or privacy questions to privacy@encoreos.io.

Services that handle what you send through this website

This list covers the marketing website and its walkthrough form. It does not describe the Encore OS product, whose data handling each organization agrees in writing before using it.

ServiceWhat it doesWhat it receivesPrivacy policy
VercelHosts this website and runs Vercel Web Analytics.Page requests, including IP address, and cookie-free page-view and event counts.vercel.com
SupabaseRuns the function that receives the walkthrough form, and stores walkthrough requests.What you enter in the form, the page you sent it from, and your IP address. To limit repeat submissions it keeps a hash of your IP address and of your email address; hashes older than two days are deleted the next time anyone submits the form.supabase.com
Google WorkspaceCarries the email alert the team gets for each new request, and our replies.The contents of your walkthrough request and any email you exchange with us.policies.google.com
Cloudflare TurnstileChecks that a form submission comes from a person rather than automated traffic.Signals from your browser, and your IP address, which it receives from your browser and from our form function.cloudflare.com