Trust & Security
Independently examined. Continuously monitored.
IMSAI handles Protected Health Information every day, so our controls are examined by an independent licensed CPA firm rather than simply asserted by us.

SOC 2® Type 2 report
Controls relevant to Security, Availability, and Confidentiality, examined by an independent licensed CPA firm.
SOC 2® Type 2
Integrity Med Solutions has received a SOC 2 Type 2 report on the organization's controls relevant to Security, Availability, and Confidentiality. A Type 2 examination assesses not only whether controls are suitably designed, but whether they operated effectively across an extended observation period — not a single point in time.
- Report type
- SOC 2 Type 2
- Observation period
- December 1, 2025 – May 31, 2026
- Trust Services Criteria
- Security, Availability, and Confidentiality
- Service auditor
- Constellation GRC CPA P.C.
Requesting the report
Use of a SOC 2 report is restricted to user entities, their auditors, and other parties with sufficient understanding of the service organization and its controls. We share the complete report package with qualified prospects and customers under NDA — get in touch and we will arrange it.
Security controls
Encryption in transit and at rest
TLS 1.3 for everything on the wire, AES-256 for everything at rest, including database storage of customer data.
Role-based access control
Granular permissions scoped per organization, so users reach only the records their role requires.
Multi-factor authentication
Required across all user accounts, with idle session locking on the platform.
Comprehensive audit trails
Every access and privileged action is logged and reviewable by your organization's administrators.
Dedicated infrastructure per organization
An isolated server environment and dedicated encryption keys per customer. Your data is never commingled with another practice's.
Continuous control monitoring
Controls are monitored continuously rather than checked once a year, with formal management review on a recurring cadence.
How we handle your data
PHI deleted after 3 days
All Protected Health Information is automatically and permanently deleted 3 days after creation. You can also delete any record manually at any time; manual deletions are purged within 24 hours.
Never used for AI training
Your PHI is processed only to produce the clinical documentation you asked for. It is never used to train models, improve algorithms, or for any other purpose — contractually guaranteed with every AI provider we use.
Zero retention with AI providers
Our agreements with AI vendors prohibit retention outright. PHI is processed in real time and discarded; it is not stored or logged on their side.
Business Associate Agreements
Signed BAAs are in place with our cloud infrastructure provider and every AI vendor that may process healthcare data on our behalf.
Full detail lives in our Privacy Policy and Terms of Service.
Infrastructure
The IMSAI production environment runs on enterprise cloud infrastructure from a major provider, under a signed Business Associate Agreement, inside an isolated private network with firewall rules reviewed on a recurring basis. Each customer organization receives a dedicated environment with independent backup and disaster recovery.
We identify our infrastructure provider and subprocessors to customers and qualified prospects under NDA, alongside the SOC 2 report package.
Questions about security?
Need our SOC 2 report, or answers for a security review? Get in touch and we'll get back to you.
Contact Us