Platform
Solutions
Company
Pricing
Register nowSign in

Trust center

Security, privacy, and compliance at ProbityCare

Everything a security reviewer asks for, published in one place — including the things we have not finished yet.

Last updated 22 August 2026

Start your security review

Request access to private documents, or send us your questionnaire and we will complete it.

Email the teamHello@probitycare.com

Overview

How we handle your patients' data.

ProbityCare stores protected health information for behavioral health and substance use treatment organizations. That means two overlapping regimes — HIPAA, and the stricter confidentiality rules for substance use records under 42 CFR Part 2 — and both are built into the product rather than written into a policy nobody reads.

This page is where we publish what is true today. Where a control is complete, it says so. Where an audit is underway, it says that instead. We would rather lose a deal to a vendor with a finished SOC 2 report than claim one we do not have.

Activein place todayIn progressunderway, not completePlannedcommitted, not started

Compliance

Compliance

Frameworks we are held to, and where each one currently stands.

HIPAAActive

Administrative, physical, and technical safeguards implemented. BAA executed before any PHI is loaded.

42 CFR Part 2Active

Consent-scoped disclosure controls for substance use disorder records, enforced at the record level.

HITECHActive

Breach notification procedures and timelines documented and tested.

SOC 2 Type IIIn progress

Audit engaged. The report is not yet available and we will publish it here when it is.

Penetration testingIn progress

Third-party application testing scheduled. Results will be published as a summary report.

HITRUST CSFPlanned

Under evaluation. We will not claim it until certification is complete.

Documents

Documents

Public documents download immediately. Private documents are released under a mutual NDA, usually within one business day.

Security whitepaperPublicDownload
Subprocessor listPublicDownload
Business Associate Agreement (template)PublicDownload
HIPAA security risk assessment summaryPrivate
Penetration test summaryPrivate
Business continuity & disaster recovery planPrivate
SOC 2 Type II reportNot yet availableIn progress

Product security

Product security

Security controls your administrators operate themselves, inside the product.

Audit loggingActive

Immutable activity log of every view, edit, signature, export, and permission change, retained seven years.

Role-based accessActive

Permissions scoped by role, program, billing entity, and record section.

Single sign-on (SSO)In progress

SAML SSO for organizations that require it.

Multi-factor authenticationActive

Available on all accounts and enforceable at the organization level.

Session controlsActive

Configurable idle timeout and forced re-authentication for sensitive actions.

Data exportActive

Customers can export their records in a usable format at any time, including at termination.

Data security

Data security

How records are protected while we hold them, and what happens when you leave.

Encryption in transitActive

TLS 1.2 or higher on all connections. HSTS enabled.

Encryption at restActive

AES-256 on all stored data, including backups and file attachments.

Data segregationActive

Each customer's records are logically separated and scoped to their tenant.

BackupsActive

Encrypted automated backups with point-in-time recovery. Restores are tested.

Data retentionActive

Retention configurable to your state and accreditation requirements.

Data erasureActive

Documented deletion process on termination, with written confirmation.

Access control

Access control

Who at ProbityCare can reach production data, and under what conditions.

Least privilegeActive

Internal access to production is limited to the smallest set of staff required.

Access reviewsActive

Internal access is reviewed on a scheduled basis and on every role change.

OffboardingActive

Access revoked as part of the documented departure checklist.

Customer access reportsActive

Administrators can produce a report of who can see what, for their own reviews.

Data privacy

Data privacy

Obligations specific to behavioral health records, including the ones HIPAA alone does not cover.

Business Associate AgreementActive

Executed with every covered entity before implementation begins.

Part 2 consent managementActive

Named recipient, purpose, scope, and expiration captured and enforced on disclosure.

Breach notificationActive

Documented process and timelines consistent with HIPAA and HITECH.

Data subject requestsActive

Process for access, correction, and accounting-of-disclosures requests.

No sale of dataActive

We do not sell, rent, or share customer data. Patient data is never used to train models.

Privacy contactActive

Privacy questions and requests are handled by a named contact, not a queue.

Infrastructure

Infrastructure

Where the platform runs and how it is monitored.

HostingActive

United States regions only. Data does not leave the country without your written instruction.

Availability monitoringActive

Continuous uptime and performance monitoring with alerting.

Status pageIn progress

Public status and incident history.

Network isolationActive

Production runs in a private network with restricted ingress.

DDoS protectionActive

Edge protection and rate limiting in front of the application.

Logging and alertingActive

Centralized infrastructure logs with automated alerting on anomalies.

Application security

Application security

How the software itself is built, reviewed, and released.

Secure developmentActive

Peer review required on every change. No direct writes to production.

Dependency scanningActive

Automated scanning of third-party libraries with tracked remediation.

Responsible disclosureActive

Report a vulnerability to Hello@probitycare.com. We respond and will not pursue good-faith researchers.

Change managementActive

Documented release process with rollback, tested before production.

Corporate security

Corporate security

The controls that apply to our own team.

Background checksActive

Performed on staff with access to production systems, where permitted by law.

Security trainingActive

Required at onboarding and annually, with completion recorded.

Device managementActive

Company devices are encrypted, managed, and remotely wipeable.

Confidentiality agreementsActive

Signed by every employee and contractor before access is granted.

Subprocessors

Subprocessors

Third parties that may process customer data, and what each one does. We post a notice on this page before adding any subprocessor that touches protected health information.

SubprocessorPurposeLocation
Amazon Web ServicesCloud infrastructure and data storageUnited States
TwilioSMS appointment reminders and notificationsUnited States
StripePatient payment processingUnited States
Gusto / ADP / PaychexPayroll export, where the customer enables itUnited States
AnthropicDocumentation assistance. No patient data is used for model training.United States

Policies

Policies

Written policies maintained by ProbityCare. Full text is available under NDA.

Acceptable use

Reviewed annually and on material change.

Access control

Reviewed annually and on material change.

Asset management

Reviewed annually and on material change.

Business continuity

Reviewed annually and on material change.

Change management

Reviewed annually and on material change.

Data classification

Reviewed annually and on material change.

Data retention & disposal

Reviewed annually and on material change.

Encryption

Reviewed annually and on material change.

Incident response

Reviewed annually and on material change.

Password

Reviewed annually and on material change.

Risk assessment

Reviewed annually and on material change.

Vendor management

Reviewed annually and on material change.

Incident response

Incident response

What happens if something goes wrong, and how to tell us if you find something.

Incident response planActive

Documented plan with defined roles, severity levels, and communication steps.

Customer notificationActive

Affected customers are contacted directly, within the timelines HIPAA requires.

Post-incident reviewActive

Every incident gets a written review, and material ones are posted to this page.

Responsible disclosureActive

Send findings to Hello@probitycare.com. We will acknowledge within two business days.

Business continuity

Business continuity

What happens if infrastructure fails, and how quickly you get back to a working chart.

Disaster recovery planActive

Documented recovery objectives with restores tested on a schedule.

Backup protectionActive

Backups are encrypted, access-controlled, and stored separately from production.

RedundancyActive

Multi-zone deployment so a single failure does not take the platform down.

Tabletop exercisesIn progress

Scheduled continuity exercises with documented outcomes.

Trust Center updates

Trust Center updates

Changes to our security posture, subprocessors, and compliance status, most recent first.

Trust Center published

This Trust Center replaces the ad-hoc security questionnaire process. Public documents are downloadable immediately; private documents are available under NDA.

SOC 2 Type II audit engaged

We have engaged an independent auditor for a SOC 2 Type II examination. We will publish the report here when the observation period closes. Until then we do not represent ourselves as SOC 2 certified.

Subprocessor list published

Our current subprocessors and the purpose of each are now listed on this page. We will post a notice here before adding any subprocessor that processes protected health information.

Questions about this page?

Security reviews, questionnaires, and BAA requests go to Hello@probitycare.com and are answered by a person, not a portal.

Found a vulnerability?

Report it to Hello@probitycare.com. We acknowledge within two business days and will not pursue good-faith research.