Alvero runs on the same trust posture as enterprise fintech.
Here's the proof — data residency, the PHI safety model, sub-processors, and how every agent action is audited.
Compliance posture
Badges reflect posture and roadmap. SOC 2 Type II is in progress; certification status will be reflected here when complete.
Data residency
All PHI is hosted in Canada — Cloudflare CA-Central and Supabase ca-central-1. No cross-border transfer of patient data.
PHI safety model
- ✓Two-way Messenger — every outbound PHI event requires human approval before it sends.
- ✓Virtual Records AI — every clinical output requires explicit doctor approval before it reaches a patient or pharmacy.
Sub-processors
Cloudflare · Supabase · Stripe · Plaid · OpenAI (zero-retention API) · Anthropic (zero-retention API). Full list and DPAs available on request.
Incident disclosure
Responsible disclosure contact and policy: /.well-known/security.txt. Confirmed PHI breaches are disclosed to affected Controllers within 72 hours.
Audit logs
Every agent action is logged with reviewer attribution. An owner-facing audit log is available in Command Centre.
Right to be forgotten
Patient-data deletion within 30 days of a verified request, coordinated with the practice as data Custodian.
Deeper references: PHIPA / HIPAA · Privacy · DPA · Security architecture