Home/Platform/Security
An integration engine moves the whole patient record before anyone has redacted it. So Grid is built so that we never see it. Our engineers diagnose from structure, metadata and error codes. Here is exactly what we do, what we've certified, and what we haven't.
Gap assessment complete, controls implemented, observation window running with an independent auditor.
Administrative, physical and technical safeguards mapped to the Security Rule. We sign BAAs.
Canadian federal and Ontario health privacy law. Grid runs in your infrastructure, so your data stays where you put it.
Our engineers diagnose from structure, metadata and error codes. We don't ask for patient data, and we advise you not to send it, to us or to anyone.
We'd rather lose a deal on a checkbox than win one on a misleading badge. Every claim on this page can be evidenced on request.
Updated as things change, not as things are hoped for.
| Framework | Status | What that means for you |
|---|---|---|
| SOC 2 Type II Security, Availability, Confidentiality | Observation window | Controls are live and being tested by an independent auditor. We can share the readiness assessment and control matrix under NDA today, and the report when issued. |
| HIPAA | Aligned · BAA | Controls mapped to 45 CFR §164 Subparts C and E. We execute Business Associate Agreements as a matter of course, not as an escalation. |
| PIPEDA | Aligned | Canadian federal private-sector privacy law. Consent, accountability, safeguards and breach reporting practices documented. |
| PHIPA (Ontario) | Aligned | We operate as a service provider / agent to health information custodians, with the logging and access records that role requires. |
| GDPR / UK GDPR | DPA available | Standard Contractual Clauses and a Data Processing Addendum available for EU and UK deployments. |
| Penetration test | Annual, third party | Independent external test at least annually plus after any material architecture change. Executive summary shared under NDA. |
Yes, as standard, wherever Grid handles protected health information. We'll also sign a DPA with Standard Contractual Clauses for EU and UK data, and we don't treat either as a negotiation of last resort.
Yes. Managed-in-your-cloud runs Grid in your AWS, Azure or GCP account: you own the keys, the network boundary and the data, and our engineers operate it under scoped, audited, time-boxed access. Fully air-gapped installations are supported too, with offline licensing and update bundles.
No. Our engineers work from message structure, metadata, headers and error codes, never patient data, and the support model is designed so that reading a record is never the path to a fix. PHI masking is on by default.
We also don't want you to send it to us. If a diagnosis seems to need a real message, de-identify it first; if you share PHI anyway, we'd rather tell you plainly that you shouldn't have. Nothing about the way we support you depends on you handing over patient data.
You set it, per project. The default is 90 days of full message archive plus 13 months of metadata, and both are configurable up or down. Legal hold suspends deletion for a named scope. Deletion is verified, not just scheduled.
You get a full export of workflows, transforms, schemas, variables and the message archive, in open formats, plus 30 days to verify it. Then we delete, and confirm the deletion in writing. Your Lua transforms and schemas are yours; there is no licence trap on the artifacts you built.
No. The AI-assisted mapping features operate on the message you give them at the moment you ask, and nothing from your traffic is retained for model training, by us or by a subprocessor. This is contractual, not a preference.
CAIQ, HECVAT, your own 300-row spreadsheet. An engineer fills it in, not a marketing team. Usually back within two business days.