Security & HIPAA Readiness

Last updated May 30, 2026

This page summarizes how AdvisorCompass protects customer data and our progress on HIPAA-aligned safeguards. It is provided on request for due diligence. It is not legal advice and does not by itself constitute a Business Associate Agreement.

Technical safeguards

  • Application-layer AES-256-GCM encryption for designated sensitive fields at rest.

  • Organization-scoped access controls and role-based permissions on all CRM APIs.

  • Automatic session logoff for staff roles (8-hour idle timeout with warning).

  • Security audit logging with administrative review.

  • Staff authentication via Google OAuth; customers should require Google 2-Step Verification for staff accounts.

Vendor BAAs (summary)

Business Associate Agreements or equivalent HIPAA terms are in place with our primary data and processing vendors where available:

  • Neon (PostgreSQL database)

  • Google Cloud (Vision OCR and eligible cloud services)

  • AWS (newsletter email delivery, where used)

  • AssemblyAI (voice transcription)

  • OpenAI (optional AI features via API)

We do not claim that every subprocessor is under a BAA. Documented exceptions and interim positions are listed on our subprocessor page.

Customer onboarding (staff 2SV, etc.) →

View subprocessor list →

Documented gaps & mitigations

Vercel (application hosting). Vercel offers a HIPAA BAA only on Enterprise. We have not purchased Enterprise. Application traffic transits Vercel without a BAA. Database ePHI remains encrypted at rest (Neon BAA plus application-layer encryption).

UploadThing (file storage). UploadThing does not offer a HIPAA BAA. Sensitive uploads use private access control, authenticated upload routes, and time-limited signed download URLs issued by our application — not public URLs. Long-term migration to Google Cloud Storage under our GCP BAA is under consideration; no migration date is set.

Sentry (error monitoring). Interim risk acceptance: production monitoring with PII collection disabled, session replay text masking, and low performance sampling. We plan to revisit a Sentry BAA before large HIPAA customer commitments.

What we do not claim

  • “Fully HIPAA compliant” or “HIPAA certified.”

  • That all subprocessors are under a BAA.

  • That we provide an executed customer BAA unless separately agreed in writing.

Contact

Security Officer: Justin Durr — info@advisorcompass.ai