Last updated: May 1, 2026(version 2026-05-01)
For our live compliance posture, sub-processor list, certifications, and security controls, visit our Trust Center .
UM-AI (operated by SSP Development LLC) applies a defense-in-depth security model covering encryption, access control, continuous monitoring, vulnerability management, and incident response. All controls are aligned with HIPAA Security Rule (45 CFR Part 164), NIST SP 800-53, and the SOC 2 Trust Services Criteria (Security, Availability, Confidentiality).
Clinical data submitted for AI evaluation is processed transiently in memory to produce results and is not persisted beyond the minimum required for audit-log integrity. Customer organizations are logically isolated from one another at the application and database layer.
In Transit — TLS 1.3
All communication between clients and the UM-AI platform is encrypted using TLS 1.3. HTTP traffic is automatically redirected to HTTPS. Older protocol versions (TLS 1.0, 1.1) are disabled at the infrastructure level (Replit). Certificate management is handled by Replit's SOC 2–certified hosting layer.
At Rest — AES-256
All data persisted to the database is encrypted at rest using AES-256 encryption managed by Neon (Neondatabase, Inc.), our serverless PostgreSQL provider. Neon holds SOC 2 Type 2 attestation and enforces encryption at the storage layer transparently to the application.
Key Management
Encryption keys are managed by Neon and Replit respectively. Application-level secrets (API keys, session secrets) are stored in Replit's encrypted secrets store and are never committed to source control or logged.
Role-Based Access Control (RBAC)
UM-AI enforces four user roles with strictly scoped permissions:
Access across organizations is strictly prohibited at the API layer. Every request is validated against the authenticated user's organization and role before data is returned.
Multi-Factor Authentication (MFA)
EHR-integrated users authenticate via VIM Canvas SDK SSO which enforces MFA at the identity provider (Inovalon) level. Direct platform users use session-based authentication with bcrypt password hashing (cost factor 12). MFA enforcement for direct-login accounts is on the roadmap and tracked in our Vanta program.
Session Management
Sessions are stored server-side in the encrypted PostgreSQL database via connect-pg-simple. Session tokens are HttpOnly, Secure-flag, and SameSite=Strict. Sessions expire after inactivity. VIM EHR sessions persist across page reloads within the authenticated EHR context using signed session validation.
Least Privilege
Database credentials follow the principle of least privilege. The application database user has no DDL privileges in production. Administrative database access requires separate, time-limited credentials.
What Is Logged
UM-AI maintains a comprehensive security audit log capturing:
Retention — 6-Year HIPAA Minimum
Audit logs are retained for a minimum of six years per HIPAA Security Rule §164.316(b)(2)(i). PHI is never stored in log entries; clinical input fields are sanitised to structured metadata (specialty, urgency level, decision outcome) before logging.
Continuous Monitoring
An in-process Intrusion Detection System (IDS) inspects all inbound HTTP traffic for anomalous patterns including SQL injection, cross-site scripting, path traversal, and brute-force login attempts. Rate limiting is enforced at the API gateway level. Security alerts are written to the audit log and escalated to the security team at security@umgpt.ai.
Assessment Cadence
Patch Management
Critical and high-severity dependency patches are applied within 30 days of disclosure. Medium/low patches are batched in the regular release cycle. Security patches to infrastructure providers (Neon, Replit) are applied automatically by those providers under their SOC 2–certified patch management programs.
Responsible Disclosure
Security researchers who discover vulnerabilities in UM-AI are encouraged to report them to security@umgpt.ai. We acknowledge reports within 2 business days and follow coordinated disclosure practices.
UM-AI maintains a formal Incident Response Plan (IRP) reviewed annually and tested via tabletop exercises. The plan covers detection, containment, eradication, recovery, and post-incident review phases.
HIPAA Breach Notification
In the event of a confirmed breach involving Protected Health Information (PHI), UM-AI will notify affected Covered Entities within 72 hours of discovering the breach, consistent with HIPAA Breach Notification Rule (45 CFR §§164.400–414) and the terms of our Business Associate Agreements. Individual notification timelines follow the requirements of applicable law.
Contact
UM-AI shares data with a limited set of sub-processors as necessary to provide the service. All sub-processors handling PHI are covered by a Business Associate Agreement (BAA) or equivalent contractual protections. The live sub-processor list is maintained in our Trust Center .