Security and data handling
Every patient care report is treated as protected health information
Controls in place
How agency data is protected
Business associate agreements
Agency data is processed only under a business associate agreement, both with the agency and with every infrastructure and model provider in the path. The agency is the covered entity; Arno Labs acts as a business associate.
Authentication and tenant isolation
Multi-factor authentication is required on every account, not offered as an option. Each agency's data is isolated from every other, and the scope of any request is determined by the authenticated session rather than by anything a client supplies.
Processing stays inside AWS
All storage and processing of agency data happens within AWS, in a HIPAA-eligible environment covered by our business associate agreement with them. Nothing in the path sits outside it: no third-party analytics, no external error reporting service, and no independent logging vendor.
Model access under the same agreement
Evaluation runs on a model accessed through AWS, covered by the same executed business associate agreement. Agency data is not used to train models, and prompts and results are not retained by the model platform.
Questions
Ask us anything, early
Questions about our security posture are welcome and we would rather have them early. We are glad to work through specifics with your privacy officer, security reviewer or counsel, and to answer a vendor security questionnaire before any agreement exists.
Request a demo
Send us your security questionnaire
We would rather answer it before a demo than after one. Send it over and we will work through it with your privacy officer or security reviewer.