Compliance

BAA & safeguards

Your Business Associate Agreement status and the technical controls that back it. Demo numbers — production ships with a signed BAA and matching attestations.

Demo stub
BAA status

Signed 2026-04-01 on behalf of CoreForge Chiropractic by Dr. Nikki Kidd. Template v2026.1.

Agreement

Signed ✓

Counter-signed by Align.ai, Inc.

Effective date

2026-04-01

Auto-renews annually

Last attestation

2026-03-15

Next review due 2026-09-15

Technical controls

Each item maps to a specific obligation in your BAA.

ControlStatusDetail
Encryption in transitActiveTLS 1.3 enforced at Vercel edge and Supabase.
Encryption at restActiveAES-256 via Supabase Postgres + S3 (Anthropic cache).
Row-level security (tenant isolation)ActiveClerk JWT practice_id claim gates every table.
Universal MFAActiveEnforced for all provider accounts via Clerk.
Comprehensive audit loggingActiveEvery AI call logged to audit_log (7-year retention).
AI: no PHI used for base-model trainingActiveAnthropic Zero-Data-Retention via Bedrock equivalent.
Subcontractor flow-down BAAsActiveAnthropic, Supabase, Clerk, Vercel, Deepgram all BAA-eligible.
Breach notification readinessActive30-day notification target (45 CFR 164.410). Template: compliance pack.
Annual penetration testPlannedScheduled post-GA with 3rd-party firm.
SOC 2 Type IIPlannedObservation window begins at 50-practice threshold.
Subcontractors (BAA-eligible)

Anthropic (Claude)

Clinical reasoning + SOAP generation

BAA On file

Deepgram

Medical ASR (transcription)

BAA On file

Supabase

Postgres + Storage + RLS

BAA On file

Clerk

Authentication + user directory

BAA On file

Vercel

Application hosting / edge

BAA On file

AWS (indirect)

Backing infra for Bedrock / S3

BAA Via Anthropic + Supabase

View AI activity log →