CareDenza runs on trust. We publish this white paper for patients, families, and organizations that want more detail on our internal security practices for transparency. Legal terms for consumers live in the Privacy Policy and Terms of Service.
1. Privacy-focused design
We use your data exclusively for your care: to build your medication list, explain what you are taking, let caregivers you invite follow along, and provide you support when you need help.
- No advertising or sale of patient data
- No third-party tracking
- Caregiver access is invite-only and revocable immediately
- You can ask us to show, correct, or delete your information at any time
We do not use health information to train public AI models, to target ads, or to build a dossier for anyone else. Details of what we collect and why are in the Privacy Policy.
2. Compliance from day one
SOC 2 and HIPAA shaped CareDenza from the start: the product, the company, and how we change production.
HIPAA
When you use CareDenza directly as a consumer, HIPAA doesn’t apply. We still apply Security Rule-aligned protections because that is the right way to handle health information. We will sign a Business Associate Agreement with healthcare organizations that offer CareDenza to their patients.
SOC 2
We use Vanta to monitor controls for a SOC 2 Type II (Security) audit concluding in October 2026 and will share the latest information as we receive it. Organizations that need a report under NDA can write to info@caredenza.com, or you can view our trust center.
3. Corporate security
We have implemented rigorous internal security practices that meet or exceed enterprise standards. A few examples:
- Mobile Device Management (MDM) is required to access corporate interfaces.
- Google Context-Aware Access (CAA) requires a company-owned device for Google-native and SAML apps. CAA does not apply to OAuth applications. For those surfaces we use mutual TLS (mTLS). mTLS is live on our source-control system (Forgejo): connections present a corporate client certificate.
- Company Google accounts require phishing-resistant hardware-backed FIDO security keys or biometric passkeys (enforced in Google Workspace) for SSO and for approval of privileged actions, absent a documented exception.
- Cloud access is least-privilege. Sensitive data and infrastructure use time-boxed just-in-time elevation, not standing administrator logins.
- Access to customer data is controlled and logged to ensure data is used only for intended purposes like support and resolving system issues.
- We perform regular internal audits using AI agents for security and data handling practices.
- We regularly validate our audit logging from services and employee endpoints.
- We audit and minimize our dependencies and continue to evolve and improve dependency controls with the changing threat landscape.
4. Where data lives
All CareDenza data is stored in Amazon Web Services data centers in the United States, on HIPAA-eligible services.
- Encryption at rest (AWS-managed keys for DynamoDB and S3)
- Encryption in transit (TLS 1.2 or higher) on every request
CareDenza may integrate with other vendors to provide additional services; each will go through a review for security and receive minimum data and access necessary to provide those services.
5. Access control
CareDenza follows AWS best practices on managing permissions. Day-to-day account access uses centralized single sign-on (SSO) with role-based access control.
Sensitive data and infrastructure use just-in-time (JIT) elevation. Engineers receive that access only for a limited window, for a specific task — not as standing administrator logins. Patient data access by staff goes through a logged broker, not raw database consoles. There are no shared patient accounts. Caregiver access is invite-only and revocable immediately.
6. Logging and change control
Reads and writes to medication data are audited. Production changes go through reviewed infrastructure-as-code.
- Audit log entries for medication data reads and writes
- Every production change traces to a pull request
- Automated tests run against every change
- Production infrastructure deploys are attested and human-approved
7. How to reach us
Questions or want to report an issue? Reach out to security@caredenza.com. Please do not include any patient data in your email. CareDenza does not operate a formal bug bounty program, but we appreciate responsible disclosures.
For the latest information, see our security page.