Curely AI
HomeCompanySecurity

Trust & Security

Enterprise-Grade Security for Clinical Data

Healthcare data is the most sensitive data in the world. Our security program is built from the ground up for the compliance requirements, threat model, and operational realities of health systems.

99.98%
Current uptime (30-day)
<180ms
Average API response
None
Last security incident
4
Pen tests per year

Compliance

Certifications & Standards

HIPAA
Certified

Health Insurance Portability and Accountability Act — full compliance across all PHI handling, storage, and transmission.

SOC 2 Type II
Certified

Annual third-party audit of security, availability, processing integrity, confidentiality, and privacy controls.

HITRUST CSF
Certified

HITRUST Common Security Framework certification covering 19 domains of healthcare cybersecurity.

ISO 27001
Certified

International information security management standard — certified through Bureau Veritas.

FedRAMP
In Progress

Federal Risk and Authorization Management Program authorization for federal agency deployments.

GDPR
Compliant

General Data Protection Regulation compliance for European patient data and EU-based health system customers.

Infrastructure

How We Protect Your Data

End-to-End Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Encryption keys are managed per-tenant using AWS KMS with automatic rotation and no Curely AI personnel access.

Tenant Isolation

Each health system customer runs in a fully isolated namespace on our Kubernetes infrastructure. Compute, storage, and network resources are never shared across tenants.

Audit Logging

Every access event, query, model inference, and administrative action is captured in immutable audit logs. Logs are retained for 7 years and exportable to your SIEM in real time.

Infrastructure Security

We run on AWS GovCloud (US) for regulated workloads. Network access is controlled via private VPC peering, WAF, DDoS protection, and mandatory MFA with phishing-resistant hardware keys for all engineers.

Vulnerability Management

Continuous SAST/DAST scanning, weekly dependency audits, and a formal penetration testing program with a top-tier healthcare security firm. Critical CVEs are patched within 24 hours.

Business Associate Agreement

We sign a HIPAA-compliant BAA with every health system customer before any PHI is transmitted. Our BAA template is available for legal review prior to contract execution.

Practices

A Comprehensive Security Program

Security isn't a feature we shipped once — it's an ongoing operational discipline. Every engineer, every deployment, and every vendor relationship is held to the same standard.

Zero-trust architecture across all internal services
Hardware security keys (YubiKey) required for all engineer access
Role-based access control with principle of least privilege
Automatic session expiration and device trust verification
Background checks and security training for all employees
Vendor security reviews for every third-party integration
Air-gapped model training environment for sensitive datasets
Red team exercises quarterly with independent security firm
Incident response plan with < 1-hour SLA for critical issues
Customer breach notification within 24 hours per HIPAA requirements

Responsible Disclosure

We welcome responsible security research on our platform. If you discover a vulnerability, please report it to our security team before any public disclosure. We respond within 24 hours and offer recognition for valid findings.

We do not pursue legal action against researchers who follow responsible disclosure practices, even if they discover vulnerabilities through active testing.

Security Contact

security@curely.ai

PGP Fingerprint

A3F2 8D19 4C7E 2B56 9A01 F483 E92C 7D34 BA56 12EF

Response SLA

Critical: < 4 hours · High: < 24 hours · Medium: < 72 hours

Ready to Start Your Security Review?

Our security team is available to walk your CISO, legal, and compliance teams through our full security program — including our SOC 2 report, penetration test results, and BAA terms.