Aequitas processes sensitive medical and legal records on behalf of physicians, law firms, and carriers. Security is foundational to the platform, not an afterthought. This page summarizes our controls; our security team is happy to review them in detail with yours.
Certifications & compliance
- SOC 2 Type II — Aequitas' parent company, TRIJ Ventures, Inc. d/b/a Kronos Health, maintains a SOC 2 Type II report covering the Aequitas platform. The report is available under NDA on request.
- HIPAA — the platform is built to align with HIPAA obligations, and we sign a Business Associate Agreement (BAA) with covered entities and their business associates.
Data protection
- Encryption in transit — all traffic is served over TLS.
- Encryption at rest — PHI, including uploaded records and generated reports, is encrypted at rest using managed KMS keys. Case data is never left in the clear.
- Isolation — each practice's data is logically isolated (multi-tenant with per-tenant scoping); one practice cannot access another's cases.
Access controls
- Least privilege — accounts and services run with the minimum access required; no standing access to data a role doesn't need.
- Per-case permissioning — counsel and staff are granted access to specific cases and files only — scoped, reviewable, and revocable at any time.
- Authentication — role-based access with token-revocation controls; optional two-step verification.
Auditability
Access, edits, permission grants, and signatures are written to an immutable, append-only audit log that supports defensibility and review. Audit records cannot be altered or deleted through the application, and are retained for the life of the account to preserve the integrity of the record. A practice's audit trail is included in its data export, and is destroyed along with the rest of its data if the practice closes its account — see the Privacy Policy.
Infrastructure & subprocessors
Aequitas runs on Amazon Web Services (AWS). We use subprocessors only as needed to operate the Service and only under appropriate agreements. Only one subprocessor receives PHI. We do not sell personal information or PHI, and we do not use PHI for advertising.
- Amazon Web Services (AWS) — compute, database, and document storage (encrypted with SSE-KMS), document text extraction, speech-to-text, and AI inference for report drafting. Receives PHI, under a signed Business Associate Agreement. All PHI is processed in HIPAA-eligible AWS services within our own AWS account; it is not sent to any third-party AI provider.
- Twilio — delivers one-time verification codes by SMS for staff sign-in (multi-factor authentication). Receives no PHI: only a practice user's mobile number and a numeric code. Examinee information is never sent by SMS.
- Stripe — payment processing and subscription billing for practices. Receives no PHI: invoice lines identify the report type and an internal report reference, never an examinee's name, claim number, or any clinical detail. Practices reconcile invoices to cases inside Aequitas, behind authentication.
We will update this page before adding any subprocessor that would receive PHI.
Human oversight
AI produces draft content; the examining physician reviews, edits, and signs. No report is final until the responsible physician approves it.
Reporting a security concern
To request our SOC 2 report (under NDA), a copy of our BAA, or to report a security concern, contact aequitas@kronosgroup.health.