Security & trust

HIPAA-compliant clinical AI for health systems. Built so PHI never leaves your environment.

Ferrum is SOC 2 Type 2 and SOC 3 certified. Controls are monitored continuously across every security domain. PHI and AI models reside in your dedicated, single-tenant cloud or on-prem environment of your choice, no exceptions.

Audited & continuously monitored
SOC 2® Type 2
Sensiba, audited
HIPAA
Compliant
How we think about security

Three principles. All the evidence in the Trust Center.

Data sovereignty
Your data stays in your control.

PHI and AI models reside in your dedicated, single-tenant cloud deployment or on-prem environment of your choice.

Zero-trust access
No standing access.

Ferrum operators have no persistent access to your environment. Privileged sessions are just-in-time, time-bound, customer-approved, and audited.

Continuous proof
Audit trails you own.

Every model action, configuration change, and access event is logged to immutable, customer-owned storage and streamable to your SIEM in real time.

Controls & coverage

Continuously monitored controls across every security domain.

App security
Code, sessions, and vulnerabilities under continuous watch.
  • Annual penetration test
  • Code review process
  • Software development lifecycle
  • Vulnerability management
  • Session lock
Data security
Encrypted in transit and at rest, by default.
  • Encryption at rest
  • SSL/TLS enforced in transit
  • Hard-disk encryption
Network security
Hardened perimeter, no public SSH, monitored endpoints.
  • Firewalls
  • Denial of public SSH
  • Malware detection software
  • Unique accounts used
Infrastructure security
Cloud storage scoped, access policies enforced.
  • Cloud data storage restricted
  • Password policy
Organization security
People, process, and resilience programs in place.
  • Acceptable use policy
  • Code of conduct
  • Security training
  • Incident response plan
  • BC/DR & disaster recovery plan
Product security
Strong authentication and clear customer terms.
  • MFA on accounts
  • System access control policy
  • Hard-disk encryption
  • Terms of service

Your security questions answered.

Yes. Ferrum maintains an active SOC 2 Type 2 report and a SOC 3 report covering security, availability, and confidentiality. Both are available in the Trust Center.

All data is encrypted at rest and SSL/TLS is enforced in transit, with hard-disk encryption applied across the environment.

Reach out through the Trust Center or your Ferrum contact, and we will share audit reports, our BAA, and supporting compliance documentation.

Yes. Ferrum operates under a Business Associate Agreement (BAA) with every customer and is architected so PHI never leaves the customer environment. Supporting compliance documentation is available in our Trust Center.

No. PHI and AI models reside in your dedicated, single-tenant cloud deployment or on-prem environment of your choice, so patient data stays under your control.

Through annual penetration testing, a formal code review process, a governed software development lifecycle, and ongoing vulnerability management.

One Fabric. Every model. Your infrastructure.

Built with security, privacy, and compliance at the core—so your team can innovate with confidence.