Skip to main content

Platform

Security Hub

Everything operators and integrators need to understand how Hebrah protects healthcare data, from platform isolation to certification and audit-ready controls.

Security Hub brings together three layers: platform isolation and encrypted connectivity, an organizational SOC2 and HIPAA certification program, and dashboard compliance controls: BAA tracking, audit checklists, and promotion gates.

Built to protect healthcare data

Real patient data never belongs on the Hebrah control plane. You develop against synthetic FHIR in sandbox; metering and provisioning run outside tenant data paths.

When you connect to a clinic, WireGuard VPN tunnels and topology-aware provisioning confirm reachability before activation. Connection workloads run in sidecar microVMs: isolated per tenant, and every webhook your app receives is HMAC-signed so you can verify it before processing.

Encrypted clinic connectivity

WireGuard VPN tunnels with peer records and flight checks verify clinic reachability before anything goes live.

Isolated data paths

Sidecar microVMs keep each connection workload separate. Synthetic FHIR and HL7 processing stays inside that boundary.

Signed webhook delivery

Every outbound event carries an HMAC signature your app can verify, built into the official Node and Python SDKs.

Certification program

Where Hebrah is on the path to SOC2 and HIPAA, designed for healthcare from day one, with no PHI on the control plane.

We are actively working toward SOC2 and HIPAA compliance with one of our trusted partners. That program covers organizational controls, technical safeguards, audit evidence, and the policies operators expect when evaluating a healthcare connectivity platform.

SOC2 in progress

Structured controls, audit readiness, and partner-led assessment toward SOC2 Type II, so enterprise customers can evaluate Hebrah with confidence.

HIPAA alignment

BAA workflows, clear PHI boundaries (synthetic sandbox only on the control plane), and healthcare-specific governance built into the platform.

Trusted partner

Our compliance journey is supported by an experienced partner. We publish updates as milestones are reached on the path to certification.

Dashboard compliance tooling

BAA tracking

Business associate agreement tracking and governance tooling help operators stay prepared for healthcare partnership reviews.

Audit-ready checklists

Structured compliance checklists document integration controls from sandbox testing through live activation workflows.

Promotion gates (coming soon)

Versioned Sandbox → Live promotion workflows require review and approval before connection changes reach production.

Product controls that help founders and operators document governance before and during live EHR connectivity.

BAA tracking, audit checklists, and promotion gates live in the operator dashboard so your team can show reviewers how sandbox testing, version history, and approval workflows protect production EHR connections.

Your path to production

How platform security, certification goals, and dashboard controls work together from first sandbox test to live activation.

Develop in Sandbox

Test integrations with synthetic FHIR and HL7 with no real PHI touches the Hebrah control plane during development.

Snapshot versions

Capture a reproducible configuration state after mapping and connectivity changes for audit trails.

Review and promote

On Pro, open PR-style promotions with diffs and AI-generated release notes. Approvals gate what moves toward Live.

Document controls

Use BAA tracking and compliance checklists in the dashboard before connecting to production EHR systems.

Talk with our team

Request a demo to walk through security architecture, or explore the developer guides for webhooks and environment versioning.

Request demo

See Hebrah in action

Walk through synthetic sandbox domains, hosted MCP tools, and governed promote-to-live workflows with our team.

Request a demo