§ Trust Center

Alvero runs on the same trust posture as enterprise fintech.

Here's the proof — data residency, the PHI safety model, sub-processors, and how every agent action is audited.

Compliance posture

HIPAASOC 2 · in progressPIPEDAGDPR · EU residents

Badges reflect posture and roadmap. SOC 2 Type II is in progress; certification status will be reflected here when complete.

Data residency

All PHI is hosted in Canada — Cloudflare CA-Central and Supabase ca-central-1. No cross-border transfer of patient data.

PHI safety model

  • Two-way Messenger — every outbound PHI event requires human approval before it sends.
  • Virtual Records AI — every clinical output requires explicit doctor approval before it reaches a patient or pharmacy.

Sub-processors

Cloudflare · Supabase · Stripe · Plaid · OpenAI (zero-retention API) · Anthropic (zero-retention API). Full list and DPAs available on request.

Incident disclosure

Responsible disclosure contact and policy: /.well-known/security.txt. Confirmed PHI breaches are disclosed to affected Controllers within 72 hours.

Audit logs

Every agent action is logged with reviewer attribution. An owner-facing audit log is available in Command Centre.

Right to be forgotten

Patient-data deletion within 30 days of a verified request, coordinated with the practice as data Custodian.

Deeper references: PHIPA / HIPAA · Privacy · DPA · Security architecture

Bring your compliance officer to the demo.Book a security review →