AI native applications to reduce medical cost

Security and trust

Controls built to SOC 2, ISO 27001 and HIPAA

SOC 2 Type II

Controls aligned

Certification in process

ISO/IEC 27001

Controls aligned

Certification in process

HIPAA

Safeguards aligned

Assessment in process

Your data

You stay in control of your data

Every client contract includes these commitments.

Model training

Models trained on your data serve only you.

Technical details under Controls

Who decides

You decide what we process and why. We act on your written instructions.

Technical details

You are the data controller and Sanoki is the data processor. If an instruction conflicts with the law that governs your contract, we tell you.

Minimization

We process only the data your service needs.

Technical details under Controls

Where it lives

Your data is stored on Amazon Web Services in the United States.

Technical details

We give you prior notice before any change of hosting location, and every transfer follows the law that governs your contract.

Deletion

We delete or return your data within 30 days of the contract ending.

Technical details under Controls

Controls

How our controls align with SOC 2, ISO 27001 and HIPAA

Control in place and aligned No matching requirement in that frameworkScheduled Planned, results reported here

ControlSOC 2ISO 27001HIPAA
Governance and risk

Risk assessment

We assess security risks on a schedule and act on what we find.

SOC 2ISO 27001HIPAA

Technical details

We document each analysis, repeat it after major system changes, and keep a treatment plan for every risk.

Security policies

Our security rules are written, approved and reviewed every year.

SOC 2ISO 27001HIPAA

Management oversight

Company leadership sets security goals and reviews how the program performs.

SOC 2ISO 27001

Technical details

Leadership also assigns security responsibilities across the team.

Security program scope

Every system that touches your data falls inside our security program.

ISO 27001

Technical details

We document the program's scope, with a statement of applicability for each control.

Internal audit and management review

We audit our own controls and fix what the audit finds.

ISO 27001

Technical details

We plan the audits in advance, leadership reviews the results, and we track each corrective action.

Legal and regulatory requirements

We track the laws and contract terms that apply to your data.

ISO 27001

Technical details

We keep a register of these requirements and review it when they change.

Fraud risk assessment

Our risk review includes fraud.

SOC 2

Technical details

That covers misuse of access and misuse of data.

System description

We document how the service works and where your data flows.

SOC 2

Technical details

We keep the description current, covering the system's boundaries, components and data flows.

Periodic compliance evaluation

We check our safeguards against health data rules on a schedule.

HIPAA

Technical details

The evaluation covers technical and non-technical safeguards, and we repeat it when operations or the environment change.

Sanctions policy

Anyone at Sanoki who breaks a security rule faces disciplinary action.

SOC 2ISO 27001HIPAA

Technical details

The disciplinary process is written down and covers security and data protection policies.

Security documentation retention

We keep security records for at least six years.

HIPAA

Technical details

This covers policies, procedures and required security records.

Business associate agreement

We sign a business associate agreement when HIPAA applies.

HIPAA

Technical details

The agreement defines safeguards, permitted uses and breach reporting for protected health information.

Access and identity

Role-based access

Each person reaches only the data their role requires.

SOC 2ISO 27001HIPAA

Technical details

Every person has an individual account, and we grant access on need to know.

Multi-factor authentication

Every login to a system that holds your data asks for a second factor.

SOC 2ISO 27001HIPAA

Technical details

This includes administrative access.

Access reviews and offboarding

We review who has access and remove it the day someone leaves or changes role.

SOC 2ISO 27001HIPAA

Background checks

People with access to your data pass a background check.

SOC 2ISO 27001HIPAA

Automatic logoff

Idle sessions close on their own.

HIPAA

Technical details

Sessions on systems that hold your data end after a defined period of inactivity.

Emergency access procedure

A written procedure lets authorized people reach critical data in an emergency.

HIPAA

Technical details

The procedure limits access to the data the emergency requires.

AI agent permissions

An AI agent sees only what the person running it can see.

SOC 2ISO 27001HIPAA

Technical details

An agent working a case inherits the permissions of the person who runs it. You decide who sees each object and each link.

Data protection

Encryption in transit

Your data is encrypted while it travels.

SOC 2ISO 27001HIPAA

Technical details

Every connection that carries your data uses TLS 1.3 or higher.

Encryption at rest

Your data is encrypted where it is stored.

SOC 2ISO 27001HIPAA

Technical details

We use AES-256 encryption.

Key and secrets management

Encryption keys and credentials live in restricted, managed stores.

SOC 2ISO 27001

Technical details

We keep them apart from code and rotate them periodically.

Client separation

Your data sits in its own environment.

SOC 2ISO 27001HIPAA

Technical details

Network segmentation and logical separation isolate your environment from every other client's.

Data minimization

We process only the data your service needs.

SOC 2ISO 27001HIPAA

Technical details

When anonymized, pseudonymized or aggregated data is enough for the purpose, we use that version.

Data used for your service

Models trained on your data serve only you.

SOC 2ISO 27001HIPAA

Technical details

This holds even after anonymization or aggregation. We never sell your data or use it for our own purposes.

Deletion or return

We delete or return your data within 30 days of the contract ending.

SOC 2ISO 27001HIPAA

Technical details

We certify the deletion in writing. We erase backup copies on their regular rotation cycle and protect them until then.

Monitoring and traceability

Audit log

We record every access, change and export of your data and keep the log for at least 12 months.

SOC 2ISO 27001HIPAA

Technical details

The log covers all personal data.

Monitoring and alerting

We monitor our systems continuously and alert the team to unusual activity.

SOC 2ISO 27001HIPAA

Technical details

Monitoring covers systems and logs, and the team reviews the alerts.

Review ledger

Every review records who decided, on which evidence, and when.

SOC 2ISO 27001HIPAA

Source traceability

Every value traces back to the document it came from.

SOC 2ISO 27001HIPAA

Infrastructure and operations

Physical security

Our servers run in Amazon Web Services data centers with controlled access.

SOC 2ISO 27001HIPAA

Technical details

Amazon Web Services provides the physical and environmental controls.

Asset and device management

We keep an inventory of our systems and manage every work device.

SOC 2ISO 27001HIPAA

Technical details

Team laptops are managed, encrypted and kept up to date.

Malware protection

Every work device runs protection against malicious software.

SOC 2ISO 27001HIPAA

Secure development and change management

Every product change is reviewed and tested before release.

SOC 2ISO 27001

Technical details

Each change needs code review, testing and approval before it reaches production. Development and production run in separate environments.

Penetration testing

An independent penetration test is scheduled.

ScheduledSOC 2ISO 27001

Technical details

After the first test, we repeat it periodically and track each finding until it is resolved.

ScheduledScheduled

Vulnerability management

We apply security patches promptly and test our infrastructure on a schedule.

SOC 2ISO 27001HIPAA

Backups

We back up your data and test that it restores.

SOC 2ISO 27001HIPAA

Continuity and recovery

The team restores the service after an outage by following a written plan.

SOC 2ISO 27001HIPAA

Technical details

The plan covers business continuity and disaster recovery.

Vendor risk management

We review every company that handles data for us.

SOC 2ISO 27001HIPAA

Technical details

We review each sub-processor before we use it and periodically after. Each one appears on this page with its function.

People

Confidentiality agreements

Everyone on the team signs a confidentiality agreement.

SOC 2ISO 27001HIPAA

Technical details

The obligation continues after employment or a contract ends.

Security training

The team trains in data protection every year.

SOC 2ISO 27001HIPAA

Data protection lead

One person at Sanoki is accountable for security and data protection.

SOC 2ISO 27001HIPAA

Incident response

Incident procedure

The team handles every security incident with a written procedure.

SOC 2ISO 27001HIPAA

Technical details

The procedure sets steps to contain the incident, limit its effects, prevent a repeat and support your report to the authority.

Client notification

If an incident touches your data, we tell you within 72 hours.

SOC 2ISO 27001HIPAA

Technical details

The 72 hours count from detection, and we add detail as the investigation advances.

Local regulations

Each contract follows the law of its jurisdiction. The controls above meet these local rules.

Colombia

  • Ley 1581 de 2012 and Decreto 1377 de 2013. The national data protection law, which treats health data as sensitive data with reinforced protection.How it is metMet by role-based access, multi-factor authentication, encryption, audit log, data minimization, deletion or return, and the incident procedure.
  • SIC Circular Externa 005 de 2017. The data authority recognizes the United States as a country with an adequate level of protection, which allows data to be hosted there.How it is metMet by encryption in transit and at rest, and vendor risk management.

United States

  • HIPAA Privacy, Security and Breach Notification Rules. They apply when your data includes protected health information of patients in the United States.How it is metMet by every control tagged HIPAA, including the business associate agreement.

Sub-processors

The companies that help us run the service

CompanyWhat it does
OpenAI, Inc.Language model inference
Anthropic, PBCLanguage model inference
Google LLC (Gemini)Language model inference and data processing
Amazon Web Services, Inc.Compute, storage and databases
Clerk, Inc.Authentication and user sessions
PostHog, Inc.Application observability and usage metrics. Receives no patient data.
Slack Technologies, LLCTeam communication and alerts

Updates

Certification is in process

  1. Our controls are in place and aligned with SOC 2, ISO 27001 and HIPAA.

Contact

Contact our security team

Security and data protection

Write to [email protected] with security questionnaires and security concerns.

Incidents

If an incident touches your data, we notify your security contact within 72 hours and send updates until it is closed.

Next steps

Start reducing medical cost
through your operation

Get a demo

See how Sanoki helps healthcare organizations reduce medical cost.

Thank you. We will be in touch at the email you shared.