Trust Center
HIPAA-compliant from day one. Enterprise-grade security designed for behavioral health — so you can focus on your clients, not your compliance checklist.
Built for healthcare
Our platform meets the strictest compliance standards in healthcare technology.
HIPAA Compliant
ActiveFull compliance with the Health Insurance Portability and Accountability Act. BAAs executed with all subprocessors.
SOC 2 Type II
In ProgressInfrastructure designed to meet SOC 2 Type II trust service criteria. Audit currently underway.
HITRUST CSF
PlannedSecurity controls aligned with the HITRUST Common Security Framework. Certification timeline 2027.
WCAG 2.1 AA
AccessibleLevel AA conformance with Web Content Accessibility Guidelines. Tested with screen readers and keyboard navigation.
Defense in depth
Multi-layered security controls implementing the administrative, physical, and technical safeguards required by the HIPAA Security Rule.
Data Encryption
AES-256 at rest · TLS 1.3 in transit
All Protected Health Information is encrypted at every layer. PHI is never stored in plaintext, and all API communications use modern TLS 1.3 encryption.
Multi-Factor Authentication
SMS + TOTP
All provider accounts support multi-factor authentication via SMS verification codes and time-based one-time passwords (TOTP) through authenticator apps.
Role-Based Access Control
4 distinct roles
Granular permissions across Owner, Admin, Clinician, and Supervisor roles. Each role has precisely scoped access to clinical data and administrative functions.
HIPAA Audit Logging
Immutable · 6+ year retention
Every access to Protected Health Information is logged in an immutable, tamper-proof audit trail. Logs are retained for 6+ years per HIPAA requirements.
Session Monitoring
IP · Device · Browser tracking
Active session monitoring tracks IP addresses, device fingerprints, and browser metadata. Suspicious activity triggers automatic alerts and session revocation.
Break-Glass Emergency Access
HIPAA §164.312(a)(2)(ii)
Emergency access procedures compliant with HIPAA Security Rule requirements. All break-glass access is fully audited and reviewed post-incident.
Powered by Google Cloud
Enterprise infrastructure backed by Google's HIPAA-eligible cloud services with a fully executed Business Associate Agreement.
Google Cloud Platform
us-central1 region
All infrastructure runs in GCP's us-central1 region with enterprise-grade SLAs, DDoS protection, and physical security controls.
Firebase Identity Platform
Enterprise authentication
Google's Identity Platform provides secure authentication with built-in brute-force protection, account enumeration prevention, and session management.
Cloud Firestore
Encryption at rest by default
HIPAA-eligible database with automatic encryption at rest, granular security rules, and real-time data synchronization across all clients.
HIPAA BAA with Google Cloud
Executed BAA
Business Associate Agreement executed with Google Cloud covering all HIPAA-eligible services used in the TrustRoom platform.
Your identity provider, your rules
Full enterprise identity management — connect your existing IdP, automate provisioning, and enforce organization-wide security policies.
SSO (SAML 2.0 / OIDC)
AvailableSelf-service SSO configuration for enterprise practices. Connect your existing identity provider — Okta, Azure AD, Google Workspace, or any SAML 2.0 / OIDC compliant IdP.
SCIM 2.0 Provisioning
AvailableAutomated user provisioning and deprovisioning via SCIM 2.0. Sync your team directory and ensure instant access revocation when clinicians leave the practice.
MFA Enforcement
AvailablePractice administrators can enforce multi-factor authentication across their entire organization. Per-user or org-wide MFA policy management.
EHR integrations
Standards-based interoperability with leading electronic health record systems. Export clinical data in any format your organization requires.
FHIR R4 API
AvailableHL7 FHIR R4 compliant API for standardized clinical data exchange. Export session notes, care plans, and patient records in interoperable format.
athenahealth
AvailableDirect integration with athenahealth for bi-directional clinical data exchange. Push notes, pull demographics, sync appointments.
Epic
PlannedEpic EHR integration for large health systems. Smart on FHIR app launch and clinical data interoperability.
Cerner (Oracle Health)
PlannedOracle Cerner integration for enterprise health system deployments. FHIR-based data exchange and single sign-on.
Trusted vendors
Every vendor with access to Protected Health Information has a signed Business Associate Agreement and meets our security requirements. We provide 30 days advance notice before adding new subprocessors.
PHI Subprocessors
Business Associate Agreement in place with each vendor. These vendors may process, store, or transmit Protected Health Information.
Customer-Controlled Integrations
Connected at the customer's discretion via OAuth. Data is shared only when a customer activates the corresponding integration.
Infrastructure Vendors
These vendors provide infrastructure services but do not process, access, or store Protected Health Information.
Security resources
Access our compliance documentation, request a BAA, or reach our security team for enterprise assessments.
Security Whitepaper
Detailed technical security architecture documentation
HECVAT
Higher Education Cloud Vendor Assessment Toolkit
SIG Questionnaire
Standardized Information Gathering questionnaire
Security questions?
We're here to help.
Our security team is available to answer questionnaires, schedule assessments, and support your procurement process.