Trust & Privacy

Your data stays yours.

Tekrata is built around a simple principle — patient data is sensitive and should be treated that way. Everything we build starts with privacy.

HIPAA Compliant GDPR Compliant End-to-End Encryption In-House Data Storage Audit Logging Data Residency Control SOC 2 — On Roadmap

Our Approach to Data Protection

Healthcare data is among the most sensitive information that exists. At Tekrata, we treat it accordingly — with strict controls, in-house infrastructure, and a zero-tolerance policy for unauthorized data sharing.

Every product we build is designed with privacy at the architecture level, not bolted on after the fact. That means encryption by default, access controls baked in, and data practices that meet or exceed regulatory requirements.

  • 1
    In-House Infrastructure

    All patient data is processed and stored on Tekrata-controlled infrastructure, with strict vendor agreements and access controls governing any external touchpoints.

  • 2
    End-to-End Encryption

    Data is encrypted in transit and at rest. Access is limited to authorized personnel with role-based controls enforced at every layer.

  • 3
    Full Audit Logging

    Every data access and system event is logged with a full audit trail — giving your compliance team complete visibility and accountability.

Regulatory Compliance

HIPAA Compliant

Tekrata operates in full compliance with the Health Insurance Portability and Accountability Act. Our systems, processes, and contracts are structured to protect Protected Health Information (PHI) in accordance with HIPAA Privacy and Security Rules. HIPAA certification is on our roadmap as we continue to scale.

GDPR Compliant

For customers and patients in the European Union, Tekrata complies with the General Data Protection Regulation. This includes lawful basis for processing, data subject rights, breach notification procedures, and data processing agreements with all relevant parties.

SOC 2 — On Our Roadmap

We are actively working toward SOC 2 Type II certification, which will provide independent third-party verification of our security, availability, and confidentiality controls. We will share our audit reports with customers upon completion.

Our Data Commitments

  • Data never sold or used for training: Your patient data is never sold or used to train external AI models.
  • Data residency control: Customers can specify where their data is stored and processed.
  • Breach notification: We will notify affected customers within 72 hours of a confirmed data breach, in line with regulatory requirements.
  • Right to deletion: Customers can request full deletion of their data at any time.
  • BAA available: We sign Business Associate Agreements with all covered entities and business associates as required under HIPAA.

Questions about our privacy practices? Contact us at info@tekrata.com