Security is a deployment decision

Confirm the controls and the contract before activation.

RegenFlow does not use a public blanket compliance claim. Deployment, data location, retention, access, subprocessors, and contract terms are reviewed for the clinic’s region and configuration.

Security readiness register

Current status, stated without a compliance shortcut.

. These statuses are pre-activation boundaries, not certifications.

Public marketing site and demo request

Public information only

Do not send PHI through the public marketing site or demo request. The request prepares an email; it is not a clinical intake channel.

BAA or regional privacy agreement

Not currently represented as executed

No BAA is currently represented as executed or included. A required agreement must be signed before a clinic sends regulated clinical data.

Clinical-data residency

No public region claim

No Canadian or U.S. clinical-data region is currently claimed. The deployment package must name and verify the selected region before activation.

Independent attestation

No SOC 2 claim

No SOC 2 attestation is currently claimed. Buyers should not infer one from product security language.

Production clinical data

Blocked before readiness review

RegenFlow does not authorize production PHI until access, retention, incident, vendor, residency, and contract requirements are verified in writing.

Public trust model

Controls the product is designed around.

These are product and workflow principles—not a substitute for a security schedule or legal review.

Human review

AI output remains a draft or surfaced context until an authorized person reviews it.

Role-aware access

Operational and clinical views are limited by the work a role is permitted to perform.

Audit history

Review and sign-off workflows preserve who acted, what changed, and when.

No inferred gaps

Unavailable source data is shown as unavailable rather than silently invented.

HIPAA, BAA, and data residency

Get the deployment facts in writing before activation.

The current security package records the hosting region, data location, retention, access roles, subprocessors, incident terms, and whether a BAA or regional privacy schedule applies to the selected configuration.

Current public status: RegenFlow does not claim that every plan includes a BAA, Canadian or U.S. data residency, or a SOC 2 attestation. Confirm those requirements in the written deployment package rather than inferring them from marketing copy.

Before launch

Security review checklist.

01

Access

Roles, permission boundaries, administrative access, and review ownership

02

Data

Data categories, location, encryption, retention, deletion, backups, and recovery

03

Vendors

Connected providers, subprocessors, usage paths, and clinic-approved integrations

04

Contracts

Security schedules, privacy terms, incident commitments, and BAA or regional terms where applicable

Onboarding range

Core setup has a timeline. Complex scope is not disguised as one.

The Launch Sprint is planned for 10 days. Advanced PHT setup is planned for 15 days. Multi-site, migration, custom security, and external connections are scoped separately because access and data decisions can change the timeline.

See implementation pricing

A working session, not a generic deck

Ask the security questions before the sales questions.

Request the current security package and use one working session to identify the data, access, residency, retention, and contract requirements for your clinic.

Book a walkthroughTake the 60-second tour30 minutes · specific to your clinic