NewScribe v2 is generally available. Handles multi-speaker visits in 23 languages.Read the launch note →
Sign in →Help CenterCall sales+1 (917) 735-8266
Security & compliance

Patient data is the most sensitive data a person owns. We built for that.

Trustro was designed from the ground up for healthcare data. Not retrofitted, not bolted on — architected for HIPAA from day one.

Compliance posture

Current certifications and compliance status. We list only what we can substantiate.

HIPAACompliant

Administrative, technical, and physical safeguards for protected health information. Trustro is fully HIPAA-compliant across all tiers.

SOC 2 Type IIAudited

Independent audit of security, availability, and confidentiality controls. Report available under NDA upon request.

BAAAvailable at every tier

Business Associate Agreements are available at every pricing tier, including Solo. No enterprise upgrade required.

HITRUST CSFIn progress — expected Q3 2026

HITRUST Common Security Framework certification is currently in progress. We do not claim HITRUST certification at this time.

Technical security controls

How we protect patient health information at the infrastructure and application layers.

Encryption at rest and in transit

All patient health information is encrypted using AES-256 at rest and TLS 1.2+ in transit. Database-level encryption covers backups and replicas.

Role-based access controls

Four permission roles — Practitioner, Biller, Staff, and Administrator — each scoped to the minimum data access required for their function. Custom roles available on Multi-location tier.

Immutable audit logs

Every access, modification, and export of patient data is logged with user identity, timestamp, and action. Audit logs are retained for seven years and cannot be modified or deleted.

Multi-tenant isolation

Each practice operates in a logically isolated tenant. Data is never commingled across organizations. Row-level security enforced at the database layer.

Sandbox and production separation

Every account includes a sandbox environment with synthetic data for training and testing. Sandbox and production environments are fully isolated — no data crosses the boundary.

Session management

Sessions expire after 24 hours of inactivity. Re-authentication required for sensitive operations. Concurrent session limits enforced per user.

Data handling principles

Clear boundaries around where patient data lives and how it moves.

No PHI on this website

This marketing site collects no protected health information. All clinical data resides in the HIPAA-scoped application environment, which is architecturally separate from marketing infrastructure.

HIPAA-scoped application boundary

Patient records, clinical notes, billing data, and scheduling information exist only inside the HIPAA-scoped application. Access requires authentication through the Trustro app with role-based permissions.

Session expiration

Active sessions expire after 24 hours. Idle timeout enforced. Re-authentication required before accessing or modifying patient records after session lapse.

Infrastructure

Trustro is hosted on SOC 2-certified cloud infrastructure with data residency in the United States. Backups are encrypted and replicated across availability zones.

We conduct regular penetration testing through independent third-party firms. Vulnerability reports are reviewed within 24 hours, and critical findings are remediated on an expedited timeline.

Security resources

Review our compliance documentation, request a BAA, or see our full list of subprocessors.