Security by design
Vested is built around least privilege, tenant isolation, authenticated encryption, phishing-resistant administrator access, and auditable human approval.
Application safeguards
- Encrypted application records, ledger fields, documents, and backup archives.
- Facility-scoped authorization with cross-tenant regression tests.
- Passkey support for privileged access and secure session controls.
- Human signature and attestation before county filing actions.
- Integrity-checked audit events and production readiness checks.
- Automated dependency, secret, resident-data, extraction, PostgreSQL, build, and static-analysis checks.
Deployment assurance
Technical controls are only one part of a compliant deployment. Customer and vendor agreements, risk analysis, workforce controls, recovery exercises, incident procedures, and independent assessment must be completed for the deployed environment. Vested does not represent that a public preview or a configuration flag alone establishes HIPAA or SOC 2 compliance.
Responsible disclosure
Report a suspected vulnerability to info@vested.health. Do not include resident information or exploit a vulnerability beyond what is necessary to demonstrate it. We will acknowledge the report and coordinate remediation.