Pre-launch preview, Polestar GRC is not live yet. Signups, billing, and email are not operational.
Skip to main content

Security

How we protect your data

Your HIPAA records are sensitive. Here is how Polestar GRC protects them, in plain terms, and which agreement covers the patient information you store with us.

Security, in plain terms

  • Encryption in transit (TLS 1.2 or higher) and at rest (AES-256 on our database volumes, file storage and backups)
  • Role-based, organization-scoped access controls and security audit logging
  • TOTP multi-factor authentication, with org-wide enforcement available
  • Time-limited, access-controlled file links for evidence and reports
  • AI features run only on Anthropic Claude models on Amazon Bedrock in US AWS regions, under our AWS business associate agreement. Text is sent after automated, pattern-based identifier redaction, which can miss identifiers; PDF files and images that AI features analyze are sent as uploaded, without redaction; prompts and outputs are not stored in our AWS account and are not used to train models
  • Security incidents affecting your data: notice without unreasonable delay and no later than 7 calendar days after we discover one
  • Insurance: we do not yet carry general liability, cyber liability or technology errors and omissions insurance in our own name (BAA Section 11.5)

Full details are in the Privacy Policy. Patient information (PHI) is governed by the Business Associate Agreement, and data outside HIPAA by the Data Protection Agreement.

Our Business Associate Agreement, in short

You can accept our Business Associate Agreement in the app before you add patient information. It is the same agreement on every plan, including the free trial. We pick the document from your organization's HIPAA role:

You accept it from the BAA Tracker in your dashboard. Your executed copy, with an execution record and document fingerprint, is stored there for download at any time, and we email you a notice with a link to it. In HIPAA mode the app does not accept new file uploads or incident narrative text until an administrator accepts the agreement.

Need a countersigned PDF or changes to the text? Write to legal@polestargrc.com before accepting.

Report a security issue

Email security@polestargrc.com. Our good-faith security research terms are in section 7 of the Acceptable Use Policy, and our security.txt lists the same contact.

See it for yourself

Start a free trial and accept the agreement for your role before you upload anything.

14 days free. No card needed to start.