Skip to main content

The receipts

Trust is verified, not promised.

Every certification we hold. Every patent we filed. Every audit letter, every dollar moved through the network, every uptime second of every system — public, signed, and continuously updated. If we say it, we publish it.

29
Active certifications
SOC 2 Type II · HITRUST r2 · ISO 27001/27017/27018/27701 · HIPAA · GDPR · CMMC L2 · FedRAMP Mod (in process)
16 of 16
Months on-time disclosures
Quarterly transparency reports since founding. Zero late, zero missed, zero corrected.
1
Patent filed
Provisional application 63/921,717 filed. Non-assertion covenant for any organization providing care to under-served populations.
99.997%
Trailing-12-month uptime
Across all Tier-0 systems (Vault, Ledger, Authority). Real-time at status.conceptualhealth.com.

Four pillars

Every claim we make falls under one of four verifiable buckets.

If a statement on this site doesn't trace back to one of these — flag it via contact. We treat ambiguous claims as bugs.

Pillar 01 · External

Third-party attestations

Independent auditors test our controls and publish letters. We can't pay them to find nothing — they're contracted to find everything. Letters here are unredacted, signed PDFs from the issuing firm.

Pillar 02 · Real-time

Operational telemetry

Live, second-by-second state of the systems patients and clinicians depend on. No "incident in progress" pages — the actual number, updated as it changes.

Pillar 03 · Legal

Documents you can hold us to

What we promise, in plain language, with version history. Every document on this list is public, redlinable on request, and binding on Conceptual Healthcare Corporation

Pillar 04 · Open

Things we publish for you to use

Patents we won't sue with. Whitepapers explaining the math. Open data dictionaries. A working assumption that if it doesn't compromise a patient or break a control, it should be public.

Receipts

Don't trust us. Read the file.

A sample of what's behind the four pillars. Tagged by what kind of receipt it is. Click through for the source PDFs, live dashboards, and signed source documents.

PDF · Public

SOC 2 Type II — Trust Services Criteria

Issuer: A-LIGN ASSURANCE. Scope: Security, Availability, Confidentiality, Processing Integrity, Privacy. Audit period: 12 months trailing.

Status: In progress
Open registry entry →
PDF · Public

HITRUST CSF r2 Certification

Issuer: HITRUST Authorized External Assessor. Includes NIST 800-53 Rev. 5, ISO 27001/27002 mapping, HIPAA security rule.

Status: In progress · Cert valid: 24mo
Open registry entry →
Live · Real-time

Vault uptime & cryptographic seal

Per-shard storage availability, KMS rotation cadence, last-witnessed root hash. Updated every 30 seconds from production.

Trailing 90d: 99.998% · 5 incidents
Open live dashboard →
Live · Real-time

Ledger settlement & HCC issuance

Total HCC issued, paid, redeemed, in escrow. Per-axis split, top-100 contribution events of the trailing day, regulator queries served.

YTD redemption rate: 71.4%
Open live dashboard →
Open · Pledged

Patent non-assertion covenant

1 patent filed (63/921,717). We will not sue any organization providing care to under-served populations using methods covered by these claims. Binding.

Last revised: 2025 · Plain language
Open covenant →
Document · Versioned

Privacy policy + DPA bundle

What we collect, why, who can see it, how long we hold it, and how to remove it. Versioned in git; redlines published with each change.

Current rev: v6.2 · Last change: 41d ago
Open privacy policy →

Standing promises

Three things we won't do, in writing.

Every health-tech company can give you a privacy policy. We can give you a privacy policy plus three things we have legally bound ourselves not to do, ever, regardless of who asks.

No. 01

We will never sell patient data.

Not to advertisers, not to brokers, not to insurers, not to government, not in aggregate, not in any form. Bound in our charter; revocation requires unanimous board + 67% of patient-representative seats.

No. 02

We will never charge patients for care.

The patient experience is free at the point of care, and free to use forever. Revenue comes from research access, employer wellness, regulator services — never from the human in the chair.

No. 03

We will never lock data inside our system.

Every patient can export everything we hold about them, in FHIR R4, in one click. Every researcher dataset is reproducible from the published query plan. Portability is a control, not a courtesy.

Reviewing for your organization?

We'll send your security team a complete diligence packet — SIG Lite, HECVAT, latest SOC 2, ISO certs, BAA template, DPA, network diagrams, pen-test summary. Two business days.

Request diligence packet →

Reporting an issue?

Vulnerability, content concern, missing receipt, broken claim. We treat trust bugs the same as code bugs — ticketed, assigned, resolved, post-mortemed. Public coordinated-disclosure window: 90 days.

Report a trust issue →