Security

Serious about data. Honest about status.

Encryption everywhere, no PHI by design, auditable AI access, and a security posture we describe exactly as it is.

01

No PHI, by architecture

Oystercatcher is built on public provider data — NPI registry, CMS datasets, Open Payments, state medical boards. We never process patient data, so there is no PHI in the platform to protect, breach, or subpoena.

Public provider data only — never patient dataHIPAA not applicable; no BAA neededProviders can opt out — suppressed across every view and export
02

Encryption & infrastructure

Data is encrypted at rest with AES-256 using AWS KMS-managed keys, and in transit with TLS. The platform runs on AWS with tenant isolation enforced at the query layer for every organization.

AES-256 at rest · AWS KMS keysTLS for all data in transitPer-organization tenant isolationExport download links expire automatically
03

Access & authentication

Role-based access control with owner, admin, and member roles. Multi-factor authentication, with TOTP MFA enforced for administrative access. Enterprise plans add single sign-on across the major identity providers.

RBAC: owner · admin · memberMFA (TOTP) — enforced for admin accessSSO: Okta · Azure AD / Entra · Google Workspace · OneLogin · custom SAML 2.0Google and Microsoft sign-in on every plan
04

Auditability & AI governance

Every integration is OAuth — no shared credentials. Connection activity is logged. AI-assistant access over MCP is consented per user, governable org-wide by admins, and every call lands in the audit log.

OAuth for every integrationAudit logs retained for 2 yearsMCP: per-user consent, org policy switch, minimum-role control72-hour breach notification commitment (see DPA)
05

SOC 2: in progress, not claimed

We are building our control environment toward a future SOC 2 examination. We are not yet certified, and we will not imply otherwise — when the report exists, it will be here.

SOC 2 program underway — not yet certifiedControl environment documented in our legal & security pages
06  /  FAQ

Security questions.

Is Oystercatcher HIPAA compliant? Do we need a BAA?

HIPAA does not apply, by design: Oystercatcher processes public professional data about providers — never patient data — so there is no PHI in the platform and no BAA is needed. Your compliance team can verify this directly against our data sources. See exactly what data we use.

Is Oystercatcher SOC 2 certified?

Not yet, and we will not imply otherwise: a SOC 2 program is underway and this page will state the certification only when we hold it. The controls described here — encryption, MFA, tenant isolation, audit logs — are in place today.

Can healthcare providers remove themselves from the platform?

Yes. Providers can opt out, and suppression applies everywhere — search, campaigns, dossiers, and exports. How we handle provider data.

Which SSO providers are supported?

Okta, Microsoft Entra ID, Google Workspace, OneLogin, and custom SAML — available on Enterprise.

What can AI assistants connected over MCP actually do?

Only what your admins allow: MCP access is governed by organization policy controls, every connection uses OAuth consent, and every call is written to the audit log.

The full detail lives in our legal pages: Security · Data Processing Addendum · Subprocessors · Vulnerability Disclosure
Closing  ·  spend your time selling

Let the agents
do the research.
Your team does
what it does best.

Want proof first? Read an example dossier — sample data, real mechanics.