PreemptiveAI
SECURITY & COMPLIANCE

HIPAA & SOC 2 Compliance

Last updated Aug 25, 2026

PreemptiveAI is committed to upholding rigorous data security, patient privacy, and regulatory compliance standards across all software, SDK integrations, and cloud infrastructure.

HIPAA Compliant

We operate as a HIPAA Business Associate to covered entities and digital health providers. We execute Business Associate Agreements (BAAs) and maintain all required administrative, physical, and technical safeguards.

SOC 2 Certified

Our systems and operational processes adhere to the AICPA SOC 2 Trust Services Criteria, ensuring independent verification of our security, data confidentiality, and system availability.

Security & Technical Safeguards

End-to-End Encryption: All data is encrypted in transit using TLS 1.3 and at rest using FIPS-validated AES-256 encryption.

Edge Signal Processing: Mobile video frames and optical signals are processed ephemerally in on-device memory. Raw video is never stored or uploaded to cloud servers.

Access Controls & MFA: Granular role-based access control (RBAC), multi-factor authentication, and the principle of least privilege are strictly enforced across all environments.

Auditing & Monitoring: Centralized, tamper-evident audit logging and continuous vulnerability assessments monitor systems for anomalies.

Business Associate Agreements (BAAs)

We sign standard and customized BAAs with healthcare systems, clinics, clinical trial sponsors, and software partners prior to handling any protected health information (PHI).

Request a BAA or Security Documentation

To request a Business Associate Agreement, review our SOC 2 documentation, or ask questions about our security practices, contact us at:

PreemptiveAI, Inc.

2801 Alaskan Way

Seattle, WA 98121