Compassly supports HIPAA-ready operations with BAA availability, strong authentication including Face ID on mobile, roles, audit logs, and encryption in transit. We do not display unverified HITRUST, PCI, or SOC 2 badges.
HIPAA has no government certification program. This mark means Compassly operates HIPAA-aligned safeguards and signs a BAA—read exactly what that covers below.
Trust foundations for regulated care teams.
Controls you can evaluate in a sales-led security review.
- 01
HIPAA-ready + BAA
HIPAA-ready operations with BAA availability for covered entities and partners. PHI in a customer environment is handled under that BAA—not website marketing copy.
BAA available - 02
Strong authentication
2FA and Face ID / Touch ID on mobile so access stays personal and accountable across clinic and residential shifts.
Identity first - 03
Roles & audit logs
Role-based access and change history designed for multi-site behavioral health teams that need a defensible trail.
Traceable actions
Control pillars, without theater.
Enterprise-style narrative, limited to practices we actually run.
Encryption in transit
Public connections to Compassly services use modern transport encryption. Additional encryption and key-handling details are shared in a sales-led review.
Access control
Least-privilege roles, authenticated sessions, and administrative controls so workforce access matches job function.
Backups & recovery posture
Customer environments are designed with backup and restore practices appropriate to clinical operations software. Recovery objectives are confirmed during security review.
Incident response
We maintain an incident-handling posture for security events, including notification paths required by a signed BAA and applicable law.
Privacy by design
Product workflows separate customer PHI from Compassly marketing data. Analytics on the public site stay off until a visitor opts in.
Sales-led review
Compliance teams can request architecture and subprocessors during evaluation. We answer those questions in diligence—not with unverified badges.
Privacy you can rely on.
What we do—and do not do—with the data behind the badge.
- PHI boundary
Your PHI is not our marketing data
Protected health information in a customer environment is handled under a signed BAA. It is never used for Compassly advertising, and production PHI is not used to train public foundation models.
No selling or ad sharing
Compassly does not sell personal information and does not share it for cross-context behavioral advertising. Site analytics stay off until a visitor opts in.
Rights you can exercise
Website visitors can request access, correction, or deletion of marketing personal information. Patient record requests are fulfilled by the provider organization that holds them.
Full detail lives in the Privacy Policy, Business Associate Agreement, and Privacy Choices.
Precise claims. No stickers.
How we talk about security on the marketing site.
No unverified badges
HITRUST, PCI DSS, and SOC 2 marks stay off this site until Compassly holds the corresponding certification or a PCI-scoped payment flow ships through a qualified partner.
Security that supports care
Controls are designed to protect protected health information without turning documentation into a paperwork obstacle.
Talk with us
Request a demo to start the security conversation your compliance team needs. Related policies live on the Legal hub.
Legal hub · Business Associate Agreement · HIPAA & BAA · Privacy Policy
See Compassly with your workflows.
Bring your programs, locations, and operational questions. We will show how Compassly fits the way your organization delivers care.
