MFA enrollment enforced for platform accounts in production. Company-admin MFA is available and opt-in per tenant, not yet on by default.
BuildingMost trust pages are a wall of green checkmarks. This one shows you what is actually live, what is being built this quarter, and the things we cannot give you yet. If you have run a vendor security review before, you know which one is more useful.
We tell you which frameworks apply to Praktend, whether we hold the certification or inherit it from our infrastructure, and what the gap is. Click any card to see controls, evidence links, and the current status in detail.
Third-party attestation covering security, availability, and confidentiality. The observation window is running. No SOC 2 report exists today. Target is Q4 2026.
View controls →We sign a BAA with every customer. On the subprocessor side, three are executed (Google Cloud 2026-06-04, Retell 2026-07-10, Stedi 2026-07-23) and three are still pending (Mailgun, Twilio, SendGrid). Section 05 lists each one and its status.
View controls →Google Cloud Platform is certified to ISO 27001, 27017, and 27018. Praktend inherits these controls by running exclusively on GCP. Praktend itself does not hold a direct ISO 27001 certificate.
View controls →Most trust pages show every control as a green checkmark. Ours shows you which ones aren't, and when they will be.
MFA enrollment enforced for platform accounts in production. Company-admin MFA is available and opt-in per tenant, not yet on by default.
BuildingSingle-axis role model. An account holds platform roles or per-company access, never both.
LiveLeast-privilege subagents. Coordinators read-only by default.
LiveQuarterly access reviews with signed-off log.
BuildingTLS 1.2 floor on public endpoints, ECDHE and AEAD ciphers only. TLS 1.3 supported.
LiveAES-256 at rest. Firestore, GCS, Cloud Run, Secret Manager.
LiveCustomer-managed encryption keys for regulated workloads.
PlannedPII scanner runs on every commit and blocks known identifier patterns.
LivePer-company isolation enforced by access decorators on every API route. Firestore rules act as a client-side backstop.
LiveExecuted BAAs with Google Cloud, Retell, and Stedi. Three subprocessor BAAs are still pending (section 05).
LiveCustomer-facing retention and deletion controls in-app.
BuildingStructured audit log on integration onboarding and approval actions.
LiveCentralized Cloud Logging on every Cloud Run service.
Live365-day retention across every PHI-adjacent service.
BuildingAnomaly alerts on privileged actions.
BuildingPre-commit hooks scan every commit for secrets and private keys.
LiveProduction changes ship through CI on a protected branch. Branch protection does not yet require a reviewer approval or a passing status check to merge.
BuildingDocumented rollback runbook for every deployed Cloud Run service.
BuildingSubprocessor register with contract-time security review.
BuildingAnnual third-party security assessments on file.
BuildingImmutable GCS snapshot written when a data source is connected. The scheduled daily snapshot job was retired 2026-07-13 and is not running today.
BuildingWritten BCP plus annual tabletop exercise.
PlannedSOC 2 Type II - observation window in motion.
BuildingIndependent annual penetration test.
PlannedOne login, role-scoped, MFA-capable.
Your systems stay yours. What we hold, we encrypt.
Inherits Google Cloud's audit posture.
Actions carry receipts.
The vendors behind Praktend, grouped by who carries the contract. Group A is our own subcontractors, where we owe you a BAA and we say plainly which ones are signed and which are not. Group B handles no protected health information by design. Group C is your own vendors, which you contract with directly and we never sign for. If you believe a vendor is missing from this list, tell us and we will correct it.
Primary PHI store and compute. Firestore, GCS, Cloud Run, KMS, Secret Manager, Logging, BigQuery, Document AI, speech services. Also covers Praktend's own self-hosted browser runner.
Mail, calendar, and drive on Praktend-provisioned mailboxes. Your own Workspace tenancy is a separate arrangement and sits in group C below.
Claude models for agent reasoning, reached through Google Vertex AI Model Garden and covered by the Google BAA. Anthropic does not offer a BAA for its direct API, so the direct API is not used for protected health information in production.
Hosted model inference for agent reasoning, embedding, and transcription. Google confirmed in writing on 2026-06-04 that Claude via Model Garden falls under the customer's GCP HIPAA BAA. There is no separate Vertex instrument.
Eligibility clearinghouse on Praktend's own account, and the default path for insurance verification. Every 270 and 271 exchange carries patient name, date of birth, and subscriber or member ID.
Voice AI for patient and payer phone work, and the default voice provider since 2026-07-13. Call audio, transcripts, dates of birth, and member IDs pass through it. Retell's voice agent is configured with an OpenAI model, and Retell's flow-down to that model provider is not yet confirmed to us. Praktend holds no BAA with OpenAI.
Primary outbound transactional email and the inbound reply webhook. Nothing structurally prevents a person or an agent from putting health information in an email body, so we treat it as PHI-capable.
Patient SMS, and the source of the phone numbers used by the voice platform. Message bodies and patient phone numbers reach it.
Standby and legacy outbound email path, used only if the primary provider is rolled back. Same PHI-capable analysis as Mailgun.
Subscription billing and card processing for your Praktend invoice. Card details go to Stripe directly. Praktend does not store card numbers, and no patient data is sent.
Read-only bank connections for bookkeeping workflows. Used only when you connect a financial account. No patient data is sent.
Scheduling for sales demos and onboarding calls with Praktend. Business contact details only. It is not connected to any patient schedule.
Bot protection on login and public forms. Sees request metadata and browser signals. No patient data is sent.
Your practice management system. Praktend reads your database using your own customer API key and holds no Open Dental data account of its own.
Transport layer for your practice management system when it is not Open Dental. It carries Dentrix, Dentrix Ascend, Dentrix Enterprise, Eaglesoft, Denticon, Curve, PracticeWorks, Dolphin, and CS OrthoTrac. Connected with your credentials.
Call tracking on your own CallRail account. Praktend holds no CallRail account and makes no CallRail API calls. It reads the notification emails CallRail sends to your mailbox. Standard CallRail plans prohibit PHI, so the healthcare tier matters here.
Your phone system. Praktend reads call audio, transcripts, voicemail, and SMS from your own account over OAuth. Default RingCentral plans are not BAA-covered, so the HIPAA-enabled plan matters here.
Your own mailbox and Drive. Praktend reads them over per-tenant OAuth that you can revoke at any time. No new vendor is introduced into the flow.
Today
10 of 24 controls live. Three subprocessor BAAs executed. Audit logs centralized.
Q3 2026
365-day log retention. Quarterly access reviews. Vendor framework signed.
Q4 2026
Auditor fieldwork, first penetration test, attestation targeted. Not yet booked or guaranteed.
2027
Annual pen test. BCP tabletop. Customer-managed keys for regulated tiers.
Send a note and we will send the document or schedule a call to walk through it. Procurement teams welcome - send your CAIQ, SIG, or custom questionnaire and we will return it within five business days.
Request a document →Business associate agreement. Signed before any PHI moves. Sample text on the HIPAA page.
Data processing addendum for regulated data flows or international processing requirements.
The live version of section 05 with effective dates and contract status.
Where we are in the SOC 2 Type II program, what is observed, expected report window.
CAIQ, SIG Lite, or your custom format. Answered with citations to controls above.
The gaps we know about, named directly. If your procurement floor sits above this, we are not the right fit today. Reach out anyway, and we will tell you straight.
In active build, clears Q4 2026. If your floor is a current Type II report today, the report itself is the one thing we cannot ship instantly. The readiness letter is available now.
Not on the 2026 roadmap. The underlying GCP platform is certified to 27001, 27017, and 27018. Praktend itself is not.
Mailgun, Twilio, and SendGrid all offer a BAA and none is signed yet. All three are PHI-capable rather than PHI-by-design, meaning nothing structurally stops health information reaching an email body or a text message. Section 05 marks each one. We would rather you read it here than find it in diligence.
Google Cloud and our clearinghouse have their own tested and attested platforms. Praktend's application has not had an independent penetration test yet. The first one is scoped alongside the SOC 2 fieldwork.
There is no live uptime dashboard and no contractual SLA today. Incident and maintenance notices go out by email. Vulnerability reports have a published route at security.txt.
Alerts go to the team directly. Response is human, not an on-call rotation. If you require a staffed SOC contractually, that is not the current shape.
Praktend is a small-team operator with an AI workforce, not a Fortune-500 vendor with a binder. If a binder is the requirement, we are not the right fit.
A direct yes or no in twenty-four hours. Procurement questionnaires welcome.
Book a demo →