Trust & Safety

Information Security

We operate in one of the most sensitive data environments there is. Security is not a feature here — it is the foundation everything else is built on.

Last updated · June 3, 2026

01 Our security program

artificialBRIDGE maintains a written information security program with administrative, technical, and physical safeguards aligned to recognized frameworks, including the HIPAA Security Rule and SOC 2 Trust Services Criteria. We review and update controls as our products and the threat landscape evolve.

02 Encryption

  • In transit: all traffic is encrypted with TLS 1.2+ (HTTPS) using modern cipher suites.
  • At rest: data stored in our managed databases and object storage is encrypted using AES-256 or provider-equivalent encryption.
  • Secrets: credentials and keys are stored in managed secret stores, never in source code.

03 Access control

  • Least-privilege access, granted by role and reviewed regularly.
  • Multi-factor authentication required for administrative and production access.
  • Production access is logged and time-bounded; offboarding revokes access promptly.

04 Infrastructure & subprocessors

We build on hardened, SOC 2-compliant cloud infrastructure rather than operating our own data centers. Core providers include:

  • Vercel — application hosting, edge network, and TLS.
  • Neon — managed Postgres database with encryption at rest.
  • Anthropic — AI model processing for product features, under enterprise data terms.

We maintain a current list of subprocessors and assess each for security and, where applicable, HIPAA readiness before use.

05 Monitoring & logging

We log application and infrastructure events, monitor for anomalous activity, and retain audit trails to support investigation. Security-relevant headers — strict transport security, X-Frame-Options, X-Content-Type-Options, a strict referrer policy, and a restrictive permissions policy — are enforced at the edge.

06 Vulnerability management

  • Dependencies are tracked and patched on a risk-prioritized basis.
  • Automated checks run in our build pipeline before changes ship.
  • We perform periodic reviews and welcome third-party testing through responsible disclosure.

07 HIPAA safeguards

For products that process protected health information, we implement the administrative, physical, and technical safeguards required by the HIPAA Security Rule, execute Business Associate Agreements with covered entities and downstream subprocessors, and apply the minimum-necessary principle. See our HIPAA Notice & Data Handling for details.

08 Data segregation

Our multi-tenant products are designed to logically isolate each organization's data, with access scoped to the authenticated tenant. Sensitive workloads can be provisioned with additional isolation on request.

09 Resilience & backups

Managed databases are backed up by our infrastructure providers with point-in-time recovery. We design for graceful degradation and maintain procedures to restore service after disruption.

10 Incident response

We maintain an incident response plan covering detection, containment, eradication, recovery, and notification. Where PHI is involved, we follow HIPAA Breach Notification Rule timelines and notify affected covered entities without unreasonable delay.

11 Responsible disclosure

If you believe you have found a security vulnerability, we want to hear from you. Please report it privately and give us reasonable time to remediate before public disclosure. We will not pursue legal action for good-faith research conducted under these guidelines.

Security Team
artificialBRIDGE LLC
Gunter, Texas, United States
security@theartificialbridge.com