Back to Home

Trust & Security

Independently examined. Continuously monitored.

IMSAI handles Protected Health Information every day, so our controls are examined by an independent licensed CPA firm rather than simply asserted by us.

AICPA SOC 2 seal

SOC 2® Type 2 report
Controls relevant to Security, Availability, and Confidentiality, examined by an independent licensed CPA firm.

SOC 2® Type 2

Integrity Med Solutions has received a SOC 2 Type 2 report on the organization's controls relevant to Security, Availability, and Confidentiality. A Type 2 examination assesses not only whether controls are suitably designed, but whether they operated effectively across an extended observation period — not a single point in time.

Report type
SOC 2 Type 2
Observation period
December 1, 2025 – May 31, 2026
Trust Services Criteria
Security, Availability, and Confidentiality
Service auditor
Constellation GRC CPA P.C.

Requesting the report

Use of a SOC 2 report is restricted to user entities, their auditors, and other parties with sufficient understanding of the service organization and its controls. We share the complete report package with qualified prospects and customers under NDA — get in touch and we will arrange it.

Security controls

Encryption in transit and at rest

TLS 1.3 for everything on the wire, AES-256 for everything at rest, including database storage of customer data.

Role-based access control

Granular permissions scoped per organization, so users reach only the records their role requires.

Multi-factor authentication

Required across all user accounts, with idle session locking on the platform.

Comprehensive audit trails

Every access and privileged action is logged and reviewable by your organization's administrators.

Dedicated infrastructure per organization

An isolated server environment and dedicated encryption keys per customer. Your data is never commingled with another practice's.

Continuous control monitoring

Controls are monitored continuously rather than checked once a year, with formal management review on a recurring cadence.

How we handle your data

PHI deleted after 3 days

All Protected Health Information is automatically and permanently deleted 3 days after creation. You can also delete any record manually at any time; manual deletions are purged within 24 hours.

Never used for AI training

Your PHI is processed only to produce the clinical documentation you asked for. It is never used to train models, improve algorithms, or for any other purpose — contractually guaranteed with every AI provider we use.

Zero retention with AI providers

Our agreements with AI vendors prohibit retention outright. PHI is processed in real time and discarded; it is not stored or logged on their side.

Business Associate Agreements

Signed BAAs are in place with our cloud infrastructure provider and every AI vendor that may process healthcare data on our behalf.

Full detail lives in our Privacy Policy and Terms of Service.

Infrastructure

The IMSAI production environment runs on enterprise cloud infrastructure from a major provider, under a signed Business Associate Agreement, inside an isolated private network with firewall rules reviewed on a recurring basis. Each customer organization receives a dedicated environment with independent backup and disaster recovery.

We identify our infrastructure provider and subprocessors to customers and qualified prospects under NDA, alongside the SOC 2 report package.

Questions about security?

Need our SOC 2 report, or answers for a security review? Get in touch and we'll get back to you.

Contact Us