Platform
Security Hub
Everything operators and integrators need to understand how Hebrah protects healthcare data, from platform isolation to certification and audit-ready controls.
Security Hub brings together three layers: platform isolation and encrypted connectivity, an organizational SOC2 and HIPAA certification program, and dashboard compliance controls: BAA tracking, audit checklists, and promotion gates.
Built to protect healthcare data
Real patient data never belongs on the Hebrah control plane. You develop against synthetic FHIR in sandbox; metering and provisioning run outside tenant data paths.
When you connect to a clinic, WireGuard VPN tunnels and topology-aware provisioning confirm reachability before activation. Connection workloads run in sidecar microVMs: isolated per tenant, and every webhook your app receives is HMAC-signed so you can verify it before processing.
Encrypted clinic connectivity
WireGuard VPN tunnels with peer records and flight checks verify clinic reachability before anything goes live.
Isolated data paths
Sidecar microVMs keep each connection workload separate. Synthetic FHIR and HL7 processing stays inside that boundary.
Signed webhook delivery
Every outbound event carries an HMAC signature your app can verify, built into the official Node and Python SDKs.
Certification program
Where Hebrah is on the path to SOC2 and HIPAA, designed for healthcare from day one, with no PHI on the control plane.
We are actively working toward SOC2 and HIPAA compliance with one of our trusted partners. That program covers organizational controls, technical safeguards, audit evidence, and the policies operators expect when evaluating a healthcare connectivity platform.
SOC2 in progress
Structured controls, audit readiness, and partner-led assessment toward SOC2 Type II, so enterprise customers can evaluate Hebrah with confidence.
HIPAA alignment
BAA workflows, clear PHI boundaries (synthetic sandbox only on the control plane), and healthcare-specific governance built into the platform.
Trusted partner
Our compliance journey is supported by an experienced partner. We publish updates as milestones are reached on the path to certification.
Dashboard compliance tooling
BAA tracking
Business associate agreement tracking and governance tooling help operators stay prepared for healthcare partnership reviews.
Audit-ready checklists
Structured compliance checklists document integration controls from sandbox testing through live activation workflows.
Promotion gates (coming soon)
Versioned Sandbox → Live promotion workflows require review and approval before connection changes reach production.
Product controls that help founders and operators document governance before and during live EHR connectivity.
BAA tracking, audit checklists, and promotion gates live in the operator dashboard so your team can show reviewers how sandbox testing, version history, and approval workflows protect production EHR connections.
Your path to production
How platform security, certification goals, and dashboard controls work together from first sandbox test to live activation.
Develop in Sandbox
Test integrations with synthetic FHIR and HL7 with no real PHI touches the Hebrah control plane during development.
Snapshot versions
Capture a reproducible configuration state after mapping and connectivity changes for audit trails.
Review and promote
On Pro, open PR-style promotions with diffs and AI-generated release notes. Approvals gate what moves toward Live.
Document controls
Use BAA tracking and compliance checklists in the dashboard before connecting to production EHR systems.
Talk with our team
Request a demo to walk through security architecture, or explore the developer guides for webhooks and environment versioning.