Security & HIPAA Readiness
Last updated May 30, 2026
This page summarizes how AdvisorCompass protects customer data and our progress on HIPAA-aligned safeguards. It is provided on request for due diligence. It is not legal advice and does not by itself constitute a Business Associate Agreement.
Technical safeguards
Application-layer AES-256-GCM encryption for designated sensitive fields at rest.
Organization-scoped access controls and role-based permissions on all CRM APIs.
Automatic session logoff for staff roles (8-hour idle timeout with warning).
Security audit logging with administrative review.
Staff authentication via Google OAuth; customers should require Google 2-Step Verification for staff accounts.
Vendor BAAs (summary)
Business Associate Agreements or equivalent HIPAA terms are in place with our primary data and processing vendors where available:
Neon (PostgreSQL database)
Google Cloud (Vision OCR and eligible cloud services)
AWS (newsletter email delivery, where used)
AssemblyAI (voice transcription)
OpenAI (optional AI features via API)
We do not claim that every subprocessor is under a BAA. Documented exceptions and interim positions are listed on our subprocessor page.
Documented gaps & mitigations
Vercel (application hosting). Vercel offers a HIPAA BAA only on Enterprise. We have not purchased Enterprise. Application traffic transits Vercel without a BAA. Database ePHI remains encrypted at rest (Neon BAA plus application-layer encryption).
UploadThing (file storage). UploadThing does not offer a HIPAA BAA. Sensitive uploads use private access control, authenticated upload routes, and time-limited signed download URLs issued by our application — not public URLs. Long-term migration to Google Cloud Storage under our GCP BAA is under consideration; no migration date is set.
Sentry (error monitoring). Interim risk acceptance: production monitoring with PII collection disabled, session replay text masking, and low performance sampling. We plan to revisit a Sentry BAA before large HIPAA customer commitments.
What we do not claim
“Fully HIPAA compliant” or “HIPAA certified.”
That all subprocessors are under a BAA.
That we provide an executed customer BAA unless separately agreed in writing.
Contact
Security Officer: Justin Durr — info@advisorcompass.ai