Skip to content

Security and data handling

Every patient care report is treated as protected health information

Controls in place

How agency data is protected

Business associate agreements

Agency data is processed only under a business associate agreement, both with the agency and with every infrastructure and model provider in the path. The agency is the covered entity; Arno Labs acts as a business associate.

Authentication and tenant isolation

Multi-factor authentication is required on every account, not offered as an option. Each agency's data is isolated from every other, and the scope of any request is determined by the authenticated session rather than by anything a client supplies.

Processing stays inside AWS

All storage and processing of agency data happens within AWS, in a HIPAA-eligible environment covered by our business associate agreement with them. Nothing in the path sits outside it: no third-party analytics, no external error reporting service, and no independent logging vendor.

Model access under the same agreement

Evaluation runs on a model accessed through AWS, covered by the same executed business associate agreement. Agency data is not used to train models, and prompts and results are not retained by the model platform.

Questions

Ask us anything, early

Questions about our security posture are welcome and we would rather have them early. We are glad to work through specifics with your privacy officer, security reviewer or counsel, and to answer a vendor security questionnaire before any agreement exists.

Contact us

Request a demo

Send us your security questionnaire

We would rather answer it before a demo than after one. Send it over and we will work through it with your privacy officer or security reviewer.