Skip to main content

Trust center

Inspect the operating boundary before the work begins.

IT Modality connects independent assurance, security controls, incident and complaint records, access standards, healthcare-data practices, and accountable human decisions to the same engagement model.

ForPeople conducting policy, privacy, security, or access review

FocusControls, ownership, evidence, and review paths

Current assurance, stated precisely.

Table — scroll horizontally to review every column.

RecordCurrent stateScope
SOC 2 Type IIDocumentedReporting period April 1, 2025 through March 31, 2026; issued May 2026
Independent penetration testCompletedLast completed April 2026; annual cadence and material-change retesting
Technology errors and omissionsActive$5 million coverage
Cyber liabilityActive$5 million coverage
AccessibilityReviewedWCAG 2.1 AA review completed July 14, 2026

Review the security assurance posture

Bound purpose, environment, access, and exit.

Every engagement records the systems, data classes, environments, permitted actions, named users, minimum privileges, evidence requirements, incident path, retention, offboarding, and receiving owner before access begins. Access is approved, time-bounded, logged, reviewed, and removed; shared accounts and silent privilege expansion are not accepted shortcuts.

Encryption, backup, restore, continuity, and incident handling are attached to the actual service boundary. Healthcare work uses HIPAA-trained personnel and BAA-ready processes where the arrangement requires them; clinical and privacy authority remain with the assigned qualified owners.

Review security and data handling
Review healthcare-data practices

Trust includes what happened when a control was tested.

IT Modality has recorded 2 Severity 2 incidents, in 2021 · 2024. Both were closed with corrective action and client notice; no Severity 2 incident remains open.

The client-complaint register contains 7 lifetime matters. During 2026 year to date, 3 were recorded: 2 resolved and 1 under independent review.

Inspect the complaint record
Review corrections

Providers inherit the same boundary.

The subprocessor register names each provider's purpose, data category, region, review date, owner, and exit path. A provider receives only the approved scope and may not silently extend access or subcontracting.

Review the subprocessor register
Review vendor readiness

AI assists. Assigned people decide.

AI may assist with inventory, retrieval, comparison, drafting, or pattern review inside an approved environment. It does not receive independent authority over clinical, legal, financial, security, personnel, contractual, or acceptance decisions. Each consequential use names the human decision owner, sources, deterministic controls, evaluation, correction path, and stop condition.

Take the evidence path that matches the decision.

  • Procurement and security: assurance, insurance, access, providers, retention, incidents, continuity, and evidence-room requests.

  • Healthcare: data flow, minimum necessary access, BAA requirements, clinical authority, and incident routing.

  • Professional assessment: Rigors integrity, assessor authority, appeals, validity, and the training/work firewall.

  • Accessibility and privacy: conformance scope, correction path, data rights, cookies, and contact channels.

Start a security conversation.

Review the legal and policy index