Security & compliance

Written for the person who has to say yes.

This page is deliberately specific, and deliberately honest about what is built, what is designed, and what is still ahead. Your security officer should be able to read it without having to translate marketing language into controls.

Start here

Where PROMETHEUS is today

What is true right now

  • The application is in beta and runs on 100% synthetic data. No real participant information has ever been processed.
  • The security and compliance layer is a specified, documented design — the v3.0 architecture — with implementation phased against a published roadmap.
  • A readiness gate technically blocks any organization from moving to live data until every control below is verified and signed off.

We would rather tell you this in the first thirty seconds than have you discover it in a questionnaire.

What we are not claiming

  • We do not hold a SOC 2 attestation today. We hold a scoped readiness plan and a target report path.
  • We do not describe ourselves as "HIPAA certified" — no such certification exists, from anyone.
  • We do not process protected health information for any customer until an executed business associate agreement and the readiness gate are both in place.

Every control on this page is either implemented, or named with the phase it lands in. We will show you which is which.

The bar we are building to

Three frameworks, one control set

Building to the current HIPAA Security Rule alone would leave a platform non-compliant the day the rewritten rule lands. PROMETHEUS is engineered to the proposed rule now.

HIPAA Security Rule

45 CFR Part 164, Subpart C. As a business associate of each PACE customer, we are directly liable for the administrative, physical and technical safeguards, the Breach Notification Rule, and the business-associate contract requirements.

The 2025 NPRM — the "2027 rule"

HHS/OCR's proposed rewrite removes the "addressable" category and makes encryption, multi-factor authentication, network segmentation, vulnerability scanning, penetration testing, asset inventory and annual business-associate certification mandatory. We designed to it before it lands.

SOC 2 & 42 CFR Part 460

Security, Availability and Confidentiality scoped for the first attestation, with Privacy and Processing Integrity staged later. PACE program requirements under 42 CFR Part 460 govern participant records and program integrity throughout.

The modern controls the 2027 rule proposes are the same controls a 2026 SOC 2 auditor already expects. That is deliberate: one control set satisfies both frameworks, so the marginal cost of SOC 2 is the auditor and the observation window rather than a second engineering program.

Architecture

Five trust zones, and what may cross between them

The written data-flow below doubles as the network map illustrating the movement of ePHI that the proposed rule will require, and as the system description a SOC 2 report must contain.

ZoneWhat lives thereHow it is reached
Zone 0 · External partners Clearinghouse and CMS / EDPS endpoints. Mutual TLS with pinned certificates and rotating keys. No inbound path from these systems into the PHI store.
Zone 1 · Public edge TLS-terminating load balancer and web application firewall — the only publicly reachable surface. Every request is authenticated against the identity provider before it reaches an application node.
Zone 2 · Application Stateless application nodes in a private subnet with no direct internet route. Role and tenant scoping enforced on every call, so one organization can never read another's data.
Zone 3 · Data (PHI) Encrypted PHI datastore, immutable audit-log store and secrets vault — each in its own isolated subnet. AES-256 at rest with managed keys, reachable only from Zone 2 over private links. No human logs in directly.
Zone 4 · Identity & operations Identity provider, logging, monitoring and backup. SAML 2.0 / OIDC with mandatory MFA. Backups encrypted and region-pinned to the United States.

Ingest

Encounter and membership files arrive over mutual TLS, land in an encrypted intake store, are checksummed and tenant-tagged, then written to the encrypted data tier. Every write is audit-logged with actor, organization, member and purpose.

Read

A user authenticates through single sign-on with MFA; the application tier enforces role and tenant scope; PHI is decrypted in memory to render. The read itself is logged, and a disclosure record is created where the Privacy Rule requires one.

Submit

Government submissions are generated and held. Transmission happens only after an explicit two-step gate, only in live mode, only over mutual TLS — and each transmission is individually audited.

Controls

The control set your questionnaire will ask about

Access & identity

  • Single sign-on via SAML 2.0 / OIDC with mandatory multi-factor authentication
  • Role-based access control, least privilege, no shared accounts
  • Demo credentials removed before any organization goes live
  • Tenant isolation enforced at the role, the query and the token

Encryption

  • AES-256 at rest with managed key rotation
  • TLS 1.3 in transit; mutual TLS to partner and government endpoints
  • No plaintext PHI path anywhere in the system
  • Signed, short-lived download links for generated artifacts

Audit & accountability

  • Append-only / write-once audit store — records cannot be altered after the fact
  • Actor, action, member, organization, purpose of use, source IP and timestamp on every access
  • Minimum seven-year retention; source IPs hashed, never stored in clear
  • Tamper detection by cryptographic hash of published figures at write time
  • Accounting of disclosures and breach records wired to the same store

Operations & resilience

  • Auto-maintained technology asset inventory generated from infrastructure state, so it cannot silently drift
  • Annual risk analysis and annual business-associate certification
  • Vulnerability scanning and penetration testing on a defined cadence
  • Contingency plan tested to a 72-hour restore objective
  • Change management with named approval on every release
The gate

How we make "not yet ready for PHI" a technical fact

Most vendors ask you to trust a policy. PROMETHEUS makes the demo-to-live transition a control: the switch is blocked in software until every item below is true and signed.

Exit criteria — all must be true before an organization may process real PHI

  • Executed business associate agreement on file for that organization, with subprocessor flow-down
  • AES-256 at rest and TLS 1.3 / mutual TLS in transit verified — no plaintext PHI path
  • Single sign-on with MFA enforced for all access; demo credentials removed
  • Immutable audit logging live; risk analysis and asset inventory complete
  • Contingency plan tested to a 72-hour restore
  • Readiness gate signed by the security and compliance lead and a co-founder

Until all six hold, the live-mode toggle is technically unavailable. That is what lets us tell you, truthfully, that PROMETHEUS cannot accidentally process real participant data before it is ready to.

Data handling

Residency, retention and who else touches it

Residency

United States only. No cross-border transfer of ePHI. Backups encrypted and region-pinned.

Retention & disposal

Defined retention and secure-disposal schedule per customer contract and the record requirements of 42 CFR Part 460.

Subprocessors

A short, named list — the EDI clearinghouse partner, the cloud host under a business associate agreement, and encrypted email where used. All covered by BAA flow-down and included in the annual certification the proposed rule requires.

Minimum necessary, by architecture. PROMETHEUS is designed to run close to where your encounter data already sits, generating findings rather than exporting copies. Less data movement is both a better security posture and a shorter questionnaire.

Diligence

What we hand your security team

Under NDA, on request — not after a purchase order.

Security & compliance specification

The full design-control document, including the control crosswalk to HIPAA and SOC 2.

ePHI data-flow map

The trust-zone architecture and written flow description in the form the rule requires.

Business associate agreement

Our template, with subprocessor flow-down, ready for your counsel to mark up.

Readiness assessment

Current control status against the roadmap phases, so nothing is a surprise at contract time.

Bring your hardest question.

We would rather answer it now than in a redline. Tell us what your security review needs to see and we will send it before the call.