Public marketing site and demo request
Public information onlyDo not send PHI through the public marketing site or demo request. The request prepares an email; it is not a clinical intake channel.
Security is a deployment decision
RegenFlow does not use a public blanket compliance claim. Deployment, data location, retention, access, subprocessors, and contract terms are reviewed for the clinic’s region and configuration.
Security readiness register
. These statuses are pre-activation boundaries, not certifications.
Do not send PHI through the public marketing site or demo request. The request prepares an email; it is not a clinical intake channel.
No BAA is currently represented as executed or included. A required agreement must be signed before a clinic sends regulated clinical data.
No Canadian or U.S. clinical-data region is currently claimed. The deployment package must name and verify the selected region before activation.
No SOC 2 attestation is currently claimed. Buyers should not infer one from product security language.
RegenFlow does not authorize production PHI until access, retention, incident, vendor, residency, and contract requirements are verified in writing.
Public trust model
These are product and workflow principles—not a substitute for a security schedule or legal review.
AI output remains a draft or surfaced context until an authorized person reviews it.
Operational and clinical views are limited by the work a role is permitted to perform.
Review and sign-off workflows preserve who acted, what changed, and when.
Unavailable source data is shown as unavailable rather than silently invented.
HIPAA, BAA, and data residency
The current security package records the hosting region, data location, retention, access roles, subprocessors, incident terms, and whether a BAA or regional privacy schedule applies to the selected configuration.
Before launch
Roles, permission boundaries, administrative access, and review ownership
Data categories, location, encryption, retention, deletion, backups, and recovery
Connected providers, subprocessors, usage paths, and clinic-approved integrations
Security schedules, privacy terms, incident commitments, and BAA or regional terms where applicable
Onboarding range
The Launch Sprint is planned for 10 days. Advanced PHT setup is planned for 15 days. Multi-site, migration, custom security, and external connections are scoped separately because access and data decisions can change the timeline.
A working session, not a generic deck
Request the current security package and use one working session to identify the data, access, residency, retention, and contract requirements for your clinic.