Audit-ready by default.
We treat your patients' data the way we'd want ours treated. The frameworks, the audits, and the paperwork — all signed and ready before you ask.
Where we're audited and certified.
Reports and attestations are available to prospects and customers under NDA via the trust center.
What's actually inside the platform.
Encryption everywhere
AES-256 at rest, TLS 1.3 in transit. Per-tenant keys on Enterprise.
Identity & SSO
SAML and OIDC with major providers; SCIM provisioning for Enterprise.
Granular RBAC
Role and resource-level permissions with audit-friendly assignments.
Audit trails
Every read, write, and consent — searchable, filterable, and exportable.
Anomaly alerts
Sign-in, export, and bulk-action anomalies surfaced to admins in real time.
Isolation
Logical isolation per tenant with optional dedicated database per Enterprise tenant.
Data residency
US, EU, or your own cloud. Cross-region replication available.
Monitoring & SLA
24/7 monitoring with paging on any production-impacting event. 99.99% target.
Vulnerability mgmt
Continuous scanning, dependency tracking, and quarterly third-party pentests.
The things procurement asks for.
BAA & DPA
Signed at onboarding for any plan handling PHI or EU data subjects.
Vendor due diligence
Subprocessor list, security questionnaires, and SOC 2 reports available under NDA.
Incident response
24-hour notification, postmortems within 5 business days for severity-1 events.
Agreements and policies.
Privacy policy
What we collect, why, how long we keep it, and the rights you have over it. We minimize data on purpose — most analytics never leave your tenant.
Terms of service
The contract between you and Oncominder, written by humans for humans. Plain-language summaries included.
Business Associate Agreement (BAA)
Signed at onboarding for any plan that handles PHI. We update it when HIPAA changes — you don't have to chase us.
Data Processing Agreement (DPA)
Signed for any tenant with EU data subjects, with our subprocessor list and Standard Contractual Clauses attached.
Need our SOC 2 report?
Sign a one-page NDA and we'll send the latest report, pentest summary, and subprocessor list in a single zip.