Security
How we protect your data
Your HIPAA records are sensitive. Here is how Polestar GRC protects them, in plain terms, and which agreement covers the patient information you store with us.
Security, in plain terms
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256 on our database volumes, file storage and backups)
- Role-based, organization-scoped access controls and security audit logging
- TOTP multi-factor authentication, with org-wide enforcement available
- Time-limited, access-controlled file links for evidence and reports
- AI features run only on Anthropic Claude models on Amazon Bedrock in US AWS regions, under our AWS business associate agreement. Text is sent after automated, pattern-based identifier redaction, which can miss identifiers; PDF files and images that AI features analyze are sent as uploaded, without redaction; prompts and outputs are not stored in our AWS account and are not used to train models
- Security incidents affecting your data: notice without unreasonable delay and no later than 7 calendar days after we discover one
- Insurance: we do not yet carry general liability, cyber liability or technology errors and omissions insurance in our own name (BAA Section 11.5)
Full details are in the Privacy Policy. Patient information (PHI) is governed by the Business Associate Agreement, and data outside HIPAA by the Data Protection Agreement.
Our Business Associate Agreement, in short
You can accept our Business Associate Agreement in the app before you add patient information. It is the same agreement on every plan, including the free trial. We pick the document from your organization's HIPAA role:
- Covered entities (providers, health plans, clearinghouses) accept the Business Associate Agreement.
- Business associates and their subcontractors accept the Subcontractor Business Associate Agreement.
- Organizations outside HIPAA accept the Data Protection Agreement.
You accept it from the BAA Tracker in your dashboard. Your executed copy, with an execution record and document fingerprint, is stored there for download at any time, and we email you a notice with a link to it. In HIPAA mode the app does not accept new file uploads or incident narrative text until an administrator accepts the agreement.
Need a countersigned PDF or changes to the text? Write to legal@polestargrc.com before accepting.
Report a security issue
Email security@polestargrc.com. Our good-faith security research terms are in section 7 of the Acceptable Use Policy, and our security.txt lists the same contact.
See it for yourself
Start a free trial and accept the agreement for your role before you upload anything.
14 days free. No card needed to start.
