Security
Security & Data Handling
How CareState handles your documents during private preview, and what is on the enterprise roadmap.
Where we are today
CareState is in private preview. We are building toward enterprise and healthcare security expectations — auditability, access controls, tenant isolation, and future HIPAA and compliance readiness. This page describes what is in place now and what is planned. We do not claim certifications we do not hold. If your security or compliance team has questions this page does not answer, we will answer them directly and in writing during pilot scoping.
In place today
Tenant isolation
AvailableTables holding operational customer data grant no direct client database access — every read and write goes through a server-side route that derives your organization and checks capability before touching a record. Two identity tables used for sign-up and membership resolution are the deliberate exception and are protected by row-level security.
Source documents are read-only
AvailableUploaded denial letters, clinical records, and payer correspondence are never modified by CareState. AI-proposed revisions are applied only to generated work product, never to the source file.
Human review is architectural
AvailableEvery AI-extracted finding lands in a review queue with status needs_review. A qualified reviewer must explicitly accept or reject it. Generated appeal documents mark unreviewed findings as pending review.
Full audit trail
AvailableEvery review action — who, when, what changed, what note was recorded — is written to an append-only audit log with the reviewer identity and timestamp. Exportable as CSV for compliance review.
Source-cited outputs
AvailableEvery finding carries a verbatim quote from the source document and its location. Citations are validated against the source text and checked for scope and polarity by a second verification pass.
Encryption in transit and at rest
Private PreviewAll traffic uses TLS in transit, and documents and database records are encrypted at rest by the underlying platform providers. Formal provider/configuration documentation of these controls is being assembled and is not yet published.
Role-based access control
AvailableOrganization roles (owner, admin, reviewer, member) are enforced server-side. Only owners and admins can invite members, change roles, or access the admin console.
Controlled document upload
AvailableDocuments enter CareState only through explicit user upload, which is validated (type, size, and content signature) before processing. CareState does not crawl, sync, or connect to customer repositories, mailboxes, or drives during private preview. Forward-to-intake email is planned and will not be enabled until it is built against the provider's verified receive contract.
Enterprise readiness roadmap
These items are planned. None are currently certified, enabled, or generally available.
HIPAA readiness & BAA
RoadmapHandling protected health information under a Business Associate Agreement is a core enterprise requirement. Readiness work — safeguards mapping, access review, and BAA templates — is planned and will be confirmed in writing before any PHI pilot.
SOC 2 Type II
RoadmapA SOC 2 audit is planned. Internal readiness work — policy inventory, evidence collection, access control review, incident response planning — is underway. We will publish the report only once an audit is complete.
ISO 27001
PlannedISO 27001 is a future enterprise compliance consideration, sequenced after SOC 2.
SAML 2.0 / OIDC single sign-on
Enterprise PilotTrue SSO integration with Okta, Entra ID, and other identity providers can be discussed and configured during enterprise pilot onboarding. Okta Bookmark Tile access is available now — note that a bookmark tile is not SSO.
SCIM provisioning
RoadmapAutomated user provisioning and deprovisioning from your identity provider. Currently, pilot users are provisioned manually by an organization admin.
Customer-managed storage
PlannedBring-your-own storage bucket so documents never leave your cloud tenancy. Under evaluation for enterprise pilots.
Configurable data retention
RoadmapPer-organization retention policies and scheduled deletion. Currently, data is retained for the duration of the pilot and deleted on request.
Document repository connectors
RoadmapSharePoint, OneDrive, Box, and S3 connectors are on the roadmap and will be prioritized by customer requirements. CareState currently supports manual upload only — it does not connect to or pull from your repositories.
Public REST API
RoadmapProgrammatic access is planned. It will not be released until authentication, permissions, rate limiting, and audit logging are production-ready.
What CareState does not do
- ✕CareState does not submit appeals, file claims, or transmit anything to a payer on your behalf.
- ✕CareState does not provide legal, clinical, billing, or coverage-determination advice.
- ✕CareState does not replace clinicians, appeals specialists, coders, utilization reviewers, or compliance teams.
- ✕CareState does not modify your source documents. They remain read-only.
- ✕CareState does not connect to, crawl, or sync from your internal systems during private preview.
- ✕CareState does not train models on your documents.
- ✕CareState does not share your data across organizations. Operational customer data has no direct client database access; every request is authorized server-side and scoped to your organization.
AI processing
CareState uses Anthropic's Claude models via API in exactly two places: reading scanned documents at intake, and drafting appeal correspondence for your review. No other feature sends anything to a model provider. Appeal drafting is evidence-grounded — the model receives only the governed evidence items attached to the case, not the underlying records — while intake reading necessarily processes the whole uploaded document, which is why every scanned upload is treated as protected health information by default.
A second verification pass independently checks every claim against its cited span for scope match, polarity match, and omitted qualifiers. Findings that fail verification are surfaced to the reviewer with the flag visible — they are not suppressed.
Read the full methodology in our working paper.
Security questions?
We will answer security and data handling questions from your team directly and in writing during pilot scoping. No question is too detailed.
Contact us about securitySOC 2 Readiness
RoadmapCareState is building toward a SOC 2 Type I report, and later Type II, across the five Trust Services Criteria. We are not currently SOC 2 certified — no vendor may claim certification without an issued auditor report, and we will update this page the moment that changes. What follows is our real, in-progress control program.
Security
Protection against unauthorized access, physical and logical.
Availability
System availability as committed or agreed.
Processing Integrity
Complete, valid, accurate, timely, authorized processing.
Confidentiality
Confidential information protected as committed.
Privacy
Personal information handled per stated commitments.
Our internal control tracker covers 20 areas including MFA and account security, role-based access control, least privilege, production and document access logging, encryption in transit and at rest, secure SDLC and code review, vulnerability management, backup and recovery, incident response, vendor management, data retention, customer data segregation, and AI-specific controls including generated output auditability and human review enforcement.