Founding Cohort 2026, 3 of 10 spots remaining · Founding rate locked for year 1 →
Authoritize.ai

We engineer PHI out of our process.

Patient information never enters our platform. Our audit intake captures only clinic name, URL, and contact email. We sign a BAA on request.

HIPAA-Ready

PHI is engineered out of our intake. We don't receive, process, or store patient information.

BAA on Request

We sign a Business Associate Agreement for any client who requires one. Template available at /legal/baa.

No PHI in Slack

Our Slack-native workflow is explicitly designed to exclude patient information from all messages.

Last updated: May 2026. We will notify clients of material changes to this list with 30 days' notice.

Sub-processorPurposeLocationDPA
Cloudflare, Inc.Pages hosting, Workers runtime, CDN, DDoS protection, Turnstile bot protection, DNS, R2 object storageDPA
Neon, Inc.Postgres database (audit submission metadata and operator data, no PHI)DPA
Anthropic, PBCContent generation engine (no PHI transmitted)DPA
Slack Technologies, LLCInternal workflow + operator notifications (no PHI transmitted)DPA
Google LLCPageSpeed Insights API, Google Business Profile API (audit signal collection, no PHI)DPA
Airtable, Inc.Internal project management (no PHI)DPA
Stripe, Inc.Payment processingDPA