Security is a deployment decision

Confirm the controls and the contract before activation.

RegenFlow does not use a public blanket compliance claim. Deployment, data location, retention, access, subprocessors, and contract terms are reviewed for the clinic's region and configuration.

Security readiness register

Current status, stated without a compliance shortcut.

Verified August 8, 2026. These statuses are pre-activation boundaries, not certifications.

Public marketing site and workflow review request

Public information only

Do not send PHI through the public marketing site or workflow review request. The request prepares an email; it is not a clinical intake channel.

BAA or regional privacy agreement

Not currently represented as executed

No BAA is currently represented as executed or included. A required agreement must be signed before a clinic sends regulated clinical data.

Clinical-data residency

No public region claim

No Canadian or U.S. clinical-data region is currently claimed. The deployment package must name and verify the selected region before activation.

Independent attestation

No SOC 2 claim

No SOC 2 attestation is currently claimed. Buyers should not infer one from product security language.

Production clinical data

Blocked before readiness review

RegenFlow does not authorize production PHI until access, retention, incident, vendor, residency, and contract requirements are verified in writing.

Public trust model

Controls the product is designed around.

These are product and workflow principles-not a substitute for a security schedule or legal review.

Human review

AI output remains a draft or surfaced context until an authorized person reviews it.

Role-aware access

Operational and clinical views are limited by the work a role is permitted to perform.

Audit history

Review and sign-off workflows preserve who acted, what changed, and when.

No inferred gaps

Unavailable source data is shown as unavailable rather than silently invented.

HIPAA, BAA, and data residency

Get the deployment facts in writing before activation.

The current security package records the hosting region, data location, retention, access roles, subprocessors, incident terms, and whether a BAA or regional privacy schedule applies to the selected configuration.

Production clinical data remains blocked until access, residency, vendors, incident terms, and contract requirements are verified in writing.

Before launch

Security review checklist.

Access
Roles, permission boundaries, administrative access, and review ownership
Data
Data categories, location, encryption, retention, deletion, backups, and recovery
Vendors
Connected providers, subprocessors, usage paths, and clinic-approved integrations
Contracts
Security schedules, privacy terms, incident commitments, and BAA or regional terms where applicable

Onboarding range

Core setup has a timeline. Complex scope is not disguised as one.

The $997 Lifetime offer covers one clinic business entity with standard updates for unlimited clinicians and staff and a limit of 25 clinic accounts. Implementation, advanced pathways, multi-site rollout, migration, custom security, and external connections are scoped separately because access and data decisions can change the timeline.

See implementation pricing

Next step

Review the written package before you review pricing.

Use one working session to name the clinic system, regulated data boundary, access roles, deployment region, retention needs, and required contract terms before activation.

View pricing