Trust center
Inspect the operating boundary before the work begins.
IT Modality connects independent assurance, security controls, incident and complaint records, access standards, healthcare-data practices, and accountable human decisions to the same engagement model.
ForPeople conducting policy, privacy, security, or access review
FocusControls, ownership, evidence, and review paths
Current assurance, stated precisely.
Table — scroll horizontally to review every column.
| Record | Current state | Scope |
|---|---|---|
| SOC 2 Type II | Documented | Reporting period April 1, 2025 through March 31, 2026; issued May 2026 |
| Independent penetration test | Completed | Last completed April 2026; annual cadence and material-change retesting |
| Technology errors and omissions | Active | $5 million coverage |
| Cyber liability | Active | $5 million coverage |
| Accessibility | Reviewed | WCAG 2.1 AA review completed July 14, 2026 |
Review the security assurance posture
Bound purpose, environment, access, and exit.
Every engagement records the systems, data classes, environments, permitted actions, named users, minimum privileges, evidence requirements, incident path, retention, offboarding, and receiving owner before access begins. Access is approved, time-bounded, logged, reviewed, and removed; shared accounts and silent privilege expansion are not accepted shortcuts.
Encryption, backup, restore, continuity, and incident handling are attached to the actual service boundary. Healthcare work uses HIPAA-trained personnel and BAA-ready processes where the arrangement requires them; clinical and privacy authority remain with the assigned qualified owners.
Review security and data handling
Review healthcare-data practices
Trust includes what happened when a control was tested.
IT Modality has recorded 2 Severity 2 incidents, in 2021 · 2024. Both were closed with corrective action and client notice; no Severity 2 incident remains open.
The client-complaint register contains 7 lifetime matters. During 2026 year to date, 3 were recorded: 2 resolved and 1 under independent review.
Inspect the complaint record
Review corrections
Providers inherit the same boundary.
The subprocessor register names each provider's purpose, data category, region, review date, owner, and exit path. A provider receives only the approved scope and may not silently extend access or subcontracting.
Review the subprocessor register
Review vendor readiness
AI assists. Assigned people decide.
AI may assist with inventory, retrieval, comparison, drafting, or pattern review inside an approved environment. It does not receive independent authority over clinical, legal, financial, security, personnel, contractual, or acceptance decisions. Each consequential use names the human decision owner, sources, deterministic controls, evaluation, correction path, and stop condition.
Take the evidence path that matches the decision.
Procurement and security: assurance, insurance, access, providers, retention, incidents, continuity, and evidence-room requests.
Healthcare: data flow, minimum necessary access, BAA requirements, clinical authority, and incident routing.
Professional assessment: Rigors integrity, assessor authority, appeals, validity, and the training/work firewall.
Accessibility and privacy: conformance scope, correction path, data rights, cookies, and contact channels.