Security & Compliance

Ember AI handles Protected Health Information for healthcare organizations every day. Here is how we keep it secure, compliant, and under your control.

SOC 2 Type IIHITRUST e1HIPAA

Certifications & attestations

SOC 2 Type II

Ember AI holds a SOC 2 Type II attestation, with controls for security, availability, and confidentiality validated continuously through regular third-party audits.

View in our Trust Center

HITRUST e1

Ember AI is HITRUST e1 certified, demonstrating foundational cybersecurity controls assessed against the HITRUST framework trusted across healthcare.

View our HITRUST assessment

HIPAA + BAA

Ember AI is fully HIPAA compliant and signs Business Associate Agreements (BAAs) with all covered entities before any PHI is exchanged.

View in our Trust Center

How we protect your data

Encryption everywhere

Protected Health Information is encrypted in transit and at rest with AES-256.

Role-based access controls

Access to data and workflows follows least-privilege, role-based controls.

Detailed audit logging

Every action is captured in detailed audit logs, so activity is traceable end to end.

Continuous monitoring

Systems are monitored continuously, with anomalies surfaced and escalated in real time.

You own your data

Customers retain complete ownership and control of their information at all times.

Human-in-the-loop AI

Exceptions route to your staff with full claim and payer context before anything is submitted.

Responsible AI, built for healthcare

Ember AI was purpose built for the nuance of healthcare, with accuracy and accountability at its core. Every AI action is explainable and auditable — determinations cite their sources, versioned histories capture what changed and who approved it, and human review is built into every workflow before anything reaches a payer.

See how this works in practice across our AI agents — each ships with evidence citations, audit trails, and human-in-the-loop controls.

Running a security review?

Our team can provide security documentation, a current subprocessor list, and answers for your review — and walk your security and IT stakeholders through the architecture.