What we hold today — and what we don't.
Fonteum does not currently hold SOC 2 (Type 1 or Type 2), HIPAA, or ISO 27001, and displays no badge it does not hold. The hosting and data tiers run on SOC 2 Type 2 attested infrastructure (Vercel, Supabase). For procurement that requires a specific attestation, contact security@fonteum.com.
How we substitute for a certification you can't yet rely on
- Attested infrastructure — hosting (Vercel) and the managed database (Supabase) both carry their own SOC 2 Type 2 reports.
- No PHI in scope — Fonteum processes only public CMS / OIG data, so the HIPAA and PHI-handling control surface does not apply.
- Radical transparency — row-level provenance on every record and a public corrections log stand in for an attestation Fonteum does not yet hold.
Certification status
Fonteum does not currently hold a SOC 2 Type 1 attestation and displays no badge it does not hold. The hosting and data tiers run on SOC 2 Type 2 attested infrastructure (Vercel, Supabase). For procurement requiring a specific attestation, contact security@fonteum.com.
Fonteum does not currently hold a SOC 2 Type 2 attestation. The upstream hosting and managed-database vendors carry their own SOC 2 Type 2 reports.
Fonteum does not currently hold a HITRUST certification. r2 (Risk-based, 2-year) is reserved for organizations handling PHI at scale; Fonteum's no-PHI architecture (see HIPAA section below) keeps it out of scope.
No-PHI attestation. Fonteum processes only public CMS data, OIG LEIE records, and de-identified provider organizational data. We do not process patient identifiers, claims data, or any Protected Health Information. HIPAA covered-entity / business-associate status is not applicable to our processing scope.
BAA (Business Associate Agreement)
BAA template available on request. Because Fonteum processes no PHI, BAA execution is typically not required for data ingestion under HIPAA — the regulatory trigger is the handling of protected health information, which our processing scope excludes. The template exists as a procurement formality for partners whose internal compliance review requires a signed BAA regardless of processing scope; the no-PHI processing clause is front-and-center in our standard template.
Request the template: security@fonteum.comwith the subject "BAA template request".
Vulnerability disclosure
Security researchers: please report vulnerabilities to security@fonteum.com. Our public security contact is also published at /.well-known/security.txt per RFC 9116.
- Acknowledgment: within 2 business days of receipt.
- Triage: initial severity assessment within 5 business days.
- Resolution: P0 issues patched within 7 days; P1 within 30 days; lower severity per published roadmap.
- Disclosure: coordinated disclosure preferred. Researchers credited on /trust#security-acknowledgments with permission.
Breach notification
If a confirmed unauthorized access to user data occurs, we notify affected parties within 24 hours of confirmation and post a public statement on /corrections-log. The notification names: scope of access, affected data classes, time window, and remediation steps. We have not had a breach to date; the policy exists so the threshold is documented, not tested.
Related Trust Center pages
- · /trust — Trust Center hub
- · /trust/data-provenance — Per-source license + redistribution posture
- · /trust/portability — Architecture + RTO/RPO + acquirer takeover path
- · /docs/integrations — REST + Delta Sharing + Snowflake + S3 roadmap
- · /research/real-act-compliance — Real ACT Compliance
- · /research/nsa-compliance — NSA Compliance