Data security

VibeCheck.luxury runs client data inside a BAA-covered boundary — and tells you exactly where.

The infrastructure, the model, the boundary, and the parts we deliberately do not claim.

Quick answer: VibeCheck.luxury runs on HIPAA-eligible infrastructure with executed BAAs. Data is encrypted at rest with pgcrypto and in transit, inside a US AWS region within the BAA boundary. PHI is handled only on the secured application subdomain, isolated from this marketing site. SOC 2 Type II is in progress. A BAA and DPA are executed at signature.
THE BOUNDARY

Where the data actually sits

US AWS region, inside the BAA boundary

Infrastructure runs in a US AWS region covered by an executed Business Associate Agreement. Encrypted at rest with pgcrypto, and encrypted in transit.

PHI isolation

Patient-facing tools and protected health information are handled exclusively on the secured application subdomain, isolated from this public site. No third-party data sale.

Your retention, your export

Your retention policy governs, not ours. Export in bulk at any time, in the format your compliance team already accepts. Integration via HL7 FHIR or API.

THE MODEL

Open weights, pinned versions

The clinical intelligence layer is powered by Gemma, Google's open-weight model family — not a black-box feature with undefined behaviour. Inference runs on Amazon Bedrock, inside AWS infrastructure covered by an executed Business Associate Agreement.

Open weights mean the model is inspectable and versioned, and cannot be changed, retired or retrained underneath your deployment. The exact model version and generation settings behind every output are pinned and disclosed — no floating "latest" that shifts under you. The model version your compliance team reviews is the model version that runs, and your clinical data never trains anyone's next release.

Every AI-generated clinical output is reviewed and signed by the licensed clinician before it enters the record. The clinical safety design →

COMPLIANCE POSTURE

Stated exactly, including what is unfinished

HIPAA

HIPAA-eligible architecture with executed BAAs. A Business Associate Agreement and Data Processing Agreement are executed at signature.

SOC 2 Type II — in progress

In progress, and described that way until a report exists. HIPAA is self-attested; an independent audit is the stronger signal, which is why we will not round this up.

There is no such thing as a HIPAA certification — the word does not exist in the regulation. A vendor offering you one is describing something that cannot be issued. That is the first thing worth checking about anyone in this category, including us.

WHAT WE DO NOT CLAIM

The absences are deliberate

We do not publish security-testing results or scan cadences. Not because there is nothing to say, but because a marketing page is the wrong surface for security theatre, and a claim we cannot substantiate on demand is worse than silence. Ask us directly under NDA and you will get a real answer.

We do not put the words "compliant" or "certified" next to HIPAA or SOC 2 anywhere on this site, because neither pairing means what buyers are usually led to think it means. And we do not claim your data is safe because we are nice people — the questions below are the ones that actually settle it.

Run the eight-question audit on us — and on everyone else you are considering →

QUESTIONS

The questions worth asking

Will you sign a BAA?

Yes. A Business Associate Agreement and a Data Processing Agreement are executed at signature. Infrastructure is HIPAA-eligible with executed BAAs in place.

Do you have a SOC 2 report?

SOC 2 Type II is in progress. It is not complete, and we will not describe it as anything other than in progress until a report is issued. HIPAA alone is self-attested; an independent audit is the stronger signal, which is exactly why we are not going to overstate where ours stands.

Which AI model runs, and does our data train it?

The clinical intelligence layer is powered by Gemma, Google's open-weight model family, with inference on Amazon Bedrock inside AWS infrastructure covered by an executed Business Associate Agreement. Open weights mean the model is inspectable and versioned; the exact model version and generation settings behind every output are pinned and disclosed, with no floating latest that shifts underneath you. Your clinical data never trains anyone's next release.

Where does protected health information live?

Patient-facing tools and PHI are handled exclusively on the secured application subdomain, isolated from this public marketing site. Infrastructure runs in a US AWS region inside the BAA boundary, encrypted at rest with pgcrypto and encrypted in transit.

Can we get our data out?

Yes, in bulk, whenever you want, and your retention policy governs rather than ours. Integration is via HL7 FHIR or API, and export comes in the format your compliance team already accepts. There is no third-party data sale.
THE CLOSE

You already own the hour. Own the days around it.