01  ·  Trust & security

Security posture.Plain English.

Most trust pages are a wall of green checkmarks. This one shows you what is actually live, what is being built this quarter, and the things we cannot give you yet. If you have run a vendor security review before, you know which one is more useful.

Last updated 2026-07-29 Posture v3.3 Region US
No public status page yet. Vulnerability reporting is published. security.txt →
10/24
Controls verifiable today
3executed
BAAs signed: Google Cloud, Retell, Stedi. Three still pending.
Q42026
SOC 2 Type II target. No report today.
24hr
Target reply on a security request
02  ·  Frameworks

The frameworks behind the posture.

In flight SOC 2
Type II
Q4 2026
Inherited · GCP ISO
27001
2025-2028
3 executed HIPAA
BAA
GCP, Retell, Stedi
At rest AES
256
Google-managed
In transit TLS
1.2+
1.3 supported. HSTS on, not preloaded.
02b  ·  Compliance frameworks

Three frameworks. Honest status on each.

We tell you which frameworks apply to Praktend, whether we hold the certification or inherit it from our infrastructure, and what the gap is. Click any card to see controls, evidence links, and the current status in detail.

Most trust pages show every control as a green checkmark. Ours shows you which ones aren't, and when they will be.

The Praktend team
03  ·  Control matrix

Every control. Honest status.

10Live 11Building 3Planned
Access · 01

MFA enrollment enforced for platform accounts in production. Company-admin MFA is available and opt-in per tenant, not yet on by default.

Building
Access · 02

Single-axis role model. An account holds platform roles or per-company access, never both.

Live
Access · 03

Least-privilege subagents. Coordinators read-only by default.

Live
Access · 04

Quarterly access reviews with signed-off log.

Building
Crypto · 05

TLS 1.2 floor on public endpoints, ECDHE and AEAD ciphers only. TLS 1.3 supported.

Live
Crypto · 06

AES-256 at rest. Firestore, GCS, Cloud Run, Secret Manager.

Live
Crypto · 07

Customer-managed encryption keys for regulated workloads.

Planned
Data · 08

PII scanner runs on every commit and blocks known identifier patterns.

Live
Data · 09

Per-company isolation enforced by access decorators on every API route. Firestore rules act as a client-side backstop.

Live
Data · 10

Executed BAAs with Google Cloud, Retell, and Stedi. Three subprocessor BAAs are still pending (section 05).

Live
Data · 11

Customer-facing retention and deletion controls in-app.

Building
Logging · 12

Structured audit log on integration onboarding and approval actions.

Live
Logging · 13

Centralized Cloud Logging on every Cloud Run service.

Live
Logging · 14

365-day retention across every PHI-adjacent service.

Building
Logging · 15

Anomaly alerts on privileged actions.

Building
Change · 16

Pre-commit hooks scan every commit for secrets and private keys.

Live
Change · 17

Production changes ship through CI on a protected branch. Branch protection does not yet require a reviewer approval or a passing status check to merge.

Building
Change · 18

Documented rollback runbook for every deployed Cloud Run service.

Building
Vendor · 19

Subprocessor register with contract-time security review.

Building
Vendor · 20

Annual third-party security assessments on file.

Building
Resilience · 21

Immutable GCS snapshot written when a data source is connected. The scheduled daily snapshot job was retired 2026-07-13 and is not running today.

Building
Resilience · 22

Written BCP plus annual tabletop exercise.

Planned
Assurance · 23

SOC 2 Type II - observation window in motion.

Building
Assurance · 24

Independent annual penetration test.

Planned
04  ·  Foundation

Four pillars hold up everything else.

I

Identity

One login, role-scoped, MFA-capable.

  • Email and password login with lockout on repeated failures. MFA enrollment is enforced for platform accounts in production; company-admin MFA is opt-in per tenant.
  • Single-axis role model. An account carries platform roles or per-company access, never both.
  • Sessions ride a short-lived signed HttpOnly cookie, not a long-lived token.
II

Data

Your systems stay yours. What we hold, we encrypt.

  • Your practice management system, Workspace, and accounting data stay in your own accounts, reached over OAuth you can revoke.
  • Praktend does hold a working copy of practice data, including PHI, in Firestore and GCS. AES-256 at rest, TLS 1.2 or higher in transit.
  • Per-tenant credentials and OAuth tokens live in a KMS-encrypted vault; platform secrets live in GCP Secret Manager. Neither lives in code.
III

Infrastructure

Inherits Google Cloud's audit posture.

  • Cloud Run behind Firebase Hosting. No on-prem, no hand-rolled boxes.
  • Google Cloud holds SOC 2, ISO 27001, ISO 27017, and ISO 27018, and offers HIPAA-eligible services. Praktend inherits those platform controls. It does not hold them itself.
  • Platform patching, physical security, and infrastructure monitoring are Google's. Application-level monitoring is ours.
IV

Audit trail

Actions carry receipts.

  • Agent actions, approvals, and integration changes write to a structured audit log.
  • Mutating routes and agent tools carry idempotency keys so a retry does not double-post. High-blast writes also record a reversal pointer.
  • Agent claims carry runtime receipts, so a number or status can be traced back to the tool call that produced it.
05  ·  Subprocessors

Who else touches your data.

The vendors behind Praktend, grouped by who carries the contract. Group A is our own subcontractors, where we owe you a BAA and we say plainly which ones are signed and which are not. Group B handles no protected health information by design. Group C is your own vendors, which you contract with directly and we never sign for. If you believe a vendor is missing from this list, tell us and we will correct it.

List last updated 2026-07-29. Email chris@praktend.com to subscribe to change notifications.

Group A. Praktend's own subprocessors. We hold the account, so we owe the BAA. Status below is the real contract status, not an aspiration.

US

Google Cloud Platform

Primary PHI store and compute. Firestore, GCS, Cloud Run, KMS, Secret Manager, Logging, BigQuery, Document AI, speech services. Also covers Praktend's own self-hosted browser runner.

BAA executed 2026-06-04 SOC 2 ISO 27001
Updated 2026-07-29
US

Google Workspace

Mail, calendar, and drive on Praktend-provisioned mailboxes. Your own Workspace tenancy is a separate arrangement and sits in group C below.

Covered by the Google BAA SOC 2 ISO 27001
Updated 2026-07-29
US

Anthropic

Claude models for agent reasoning, reached through Google Vertex AI Model Garden and covered by the Google BAA. Anthropic does not offer a BAA for its direct API, so the direct API is not used for protected health information in production.

Via Vertex, under the Google BAA No direct-API BAA
Updated 2026-07-29
US

Vertex AI

Hosted model inference for agent reasoning, embedding, and transcription. Google confirmed in writing on 2026-06-04 that Claude via Model Garden falls under the customer's GCP HIPAA BAA. There is no separate Vertex instrument.

Covered by the GCP BAA US residency
Updated 2026-07-29
US

Stedi

Eligibility clearinghouse on Praktend's own account, and the default path for insurance verification. Every 270 and 271 exchange carries patient name, date of birth, and subscriber or member ID.

BAA executed 2026-07-23 SOC 2 Type II HITRUST r2
Updated 2026-07-29
US

Retell

Voice AI for patient and payer phone work, and the default voice provider since 2026-07-13. Call audio, transcripts, dates of birth, and member IDs pass through it. Retell's voice agent is configured with an OpenAI model, and Retell's flow-down to that model provider is not yet confirmed to us. Praktend holds no BAA with OpenAI.

BAA executed 2026-07-10 Flow-down unconfirmed
Updated 2026-07-29
US

Mailgun

Primary outbound transactional email and the inbound reply webhook. Nothing structurally prevents a person or an agent from putting health information in an email body, so we treat it as PHI-capable.

BAA available, not signed PHI-capable
Updated 2026-07-29
US

Twilio

Patient SMS, and the source of the phone numbers used by the voice platform. Message bodies and patient phone numbers reach it.

BAA available, not signed PHI-capable
Updated 2026-07-29
US

SendGrid

Standby and legacy outbound email path, used only if the primary provider is rolled back. Same PHI-capable analysis as Mailgun.

BAA available, not signed Standby path
Updated 2026-07-29

Group B. No protected health information by design. These vendors sit outside the PHI path. The control is engineering discipline and payload-level blocks, not a BAA.

US

Stripe

Subscription billing and card processing for your Praktend invoice. Card details go to Stripe directly. Praktend does not store card numbers, and no patient data is sent.

No PHI by design PCI DSS Level 1
Updated 2026-07-29
US

Plaid

Read-only bank connections for bookkeeping workflows. Used only when you connect a financial account. No patient data is sent.

No PHI by design Read-only
Updated 2026-07-29
US

Cal.com

Scheduling for sales demos and onboarding calls with Praktend. Business contact details only. It is not connected to any patient schedule.

No PHI by design Sales only
Updated 2026-07-29
US

Google reCAPTCHA

Bot protection on login and public forms. Sees request metadata and browser signals. No patient data is sent.

No PHI by design Login and forms
Updated 2026-07-29

Group C. Your vendors, not ours. You hold the account and you sign the BAA. Praktend holds no contract with these vendors and signs nothing on your behalf. We list them anyway, because pretending they are not in the picture would not help your review. Several of them contractually prohibit PHI on their standard plans, so check that you are on the healthcare tier.

Yours

Open Dental

Your practice management system. Praktend reads your database using your own customer API key and holds no Open Dental data account of its own.

You sign the BAA Praktend reads only
Updated 2026-07-29
Yours

NexHealth

Transport layer for your practice management system when it is not Open Dental. It carries Dentrix, Dentrix Ascend, Dentrix Enterprise, Eaglesoft, Denticon, Curve, PracticeWorks, Dolphin, and CS OrthoTrac. Connected with your credentials.

You sign the BAA 9 PMS brands
Updated 2026-07-29
Yours

CallRail

Call tracking on your own CallRail account. Praktend holds no CallRail account and makes no CallRail API calls. It reads the notification emails CallRail sends to your mailbox. Standard CallRail plans prohibit PHI, so the healthcare tier matters here.

You sign the BAA Healthcare tier needed
Updated 2026-07-29
Yours

RingCentral

Your phone system. Praktend reads call audio, transcripts, voicemail, and SMS from your own account over OAuth. Default RingCentral plans are not BAA-covered, so the HIPAA-enabled plan matters here.

You sign the BAA HIPAA plan needed
Updated 2026-07-29
Yours

Your Google Workspace

Your own mailbox and Drive. Praktend reads them over per-tenant OAuth that you can revoke at any time. No new vendor is introduced into the flow.

You sign the BAA Revocable OAuth
Updated 2026-07-29
06  ·  Roadmap

What's being built, with dates.

Today

Foundation in place.

10 of 24 controls live. Three subprocessor BAAs executed. Audit logs centralized.

Q3 2026

Observation window.

365-day log retention. Quarterly access reviews. Vendor framework signed.

Q4 2026

SOC 2 Type II.

Auditor fieldwork, first penetration test, attestation targeted. Not yet booked or guaranteed.

2027

Mature program.

Annual pen test. BCP tabletop. Customer-managed keys for regulated tiers.

07  ·  Documents

Available on request.

Send a note and we will send the document or schedule a call to walk through it. Procurement teams welcome - send your CAIQ, SIG, or custom questionnaire and we will return it within five business days.

Request a document →
  • 01

    BAA

    Business associate agreement. Signed before any PHI moves. Sample text on the HIPAA page.

    Same day
  • 02

    DPA

    Data processing addendum for regulated data flows or international processing requirements.

    Same day
  • 03

    Subprocessor list

    The live version of section 05 with effective dates and contract status.

    Same day
  • 04

    SOC 2 readiness letter

    Where we are in the SOC 2 Type II program, what is observed, expected report window.

    24 hours
  • 05

    Security questionnaire

    CAIQ, SIG Lite, or your custom format. Answered with citations to controls above.

    5 days
08  ·  The honest part

What we cannot give you yet.

The gaps we know about, named directly. If your procurement floor sits above this, we are not the right fit today. Reach out anyway, and we will tell you straight.

  1. 01

    SOC 2 Type II report

    In active build, clears Q4 2026. If your floor is a current Type II report today, the report itself is the one thing we cannot ship instantly. The readiness letter is available now.

  2. 02

    ISO 27001 certification

    Not on the 2026 roadmap. The underlying GCP platform is certified to 27001, 27017, and 27018. Praktend itself is not.

  3. 03

    Three subprocessor BAAs are still unsigned

    Mailgun, Twilio, and SendGrid all offer a BAA and none is signed yet. All three are PHI-capable rather than PHI-by-design, meaning nothing structurally stops health information reaching an email body or a text message. Section 05 marks each one. We would rather you read it here than find it in diligence.

  4. 04

    No completed penetration test of our own product

    Google Cloud and our clearinghouse have their own tested and attested platforms. Praktend's application has not had an independent penetration test yet. The first one is scoped alongside the SOC 2 fieldwork.

  5. 05

    No public status page

    There is no live uptime dashboard and no contractual SLA today. Incident and maintenance notices go out by email. Vulnerability reports have a published route at security.txt.

  6. 06

    24/7 security operations center

    Alerts go to the team directly. Response is human, not an on-call rotation. If you require a staffed SOC contractually, that is not the current shape.

  7. 07

    A thousand-page security dossier

    Praktend is a small-team operator with an AI workforce, not a Fortune-500 vendor with a binder. If a binder is the requirement, we are not the right fit.

Send us your security question.

A direct yes or no in twenty-four hours. Procurement questionnaires welcome.

Book a demo
chris@praktend.com  ·  reply within twenty-four hours