Security and compliance, verified before launch.
Altehra is in pre-alpha and does not accept production PHI. This page states the controls implemented today and the evidence required before launch.
Encryption at rest and in transit
Production launch is blocked until encryption, key management, TLS, and data-flow settings are verified for every contracted service.
HIPAA-eligible infrastructure
Altehra accepts no PHI until required BAAs are executed and each vendor account is placed in its documented HIPAA-ready configuration.
Independent assurance
SOC 2 and HITRUST status will be stated here only after an independent report or certification is complete and available for review.
Role-based access control
Server-side role gates separate clinical, billing, administrative, managed-service, parent, and assigned-caseload access.
Append-only audit controls
Audit records are append-only at the database layer. Full workflow coverage and the final retention policy remain production release gates.
Backup and disaster recovery
Production is blocked until backup retention, RTO/RPO, emergency access, and a successful restore drill are documented and approved.
Business Associate Agreements
Before processing PHI, Altehra will execute a BAA with each covered customer and every applicable subprocessor. Vendor availability or an API key alone does not satisfy this gate; the signed agreement and HIPAA-ready account configuration must both be recorded in the release register.
Pre-alpha security documentation is available for design-partner review. Production compliance claims will be published only after the corresponding evidence is approved.