Security & Compliance

Prepared for regulated health data

Cierta is currently operated under a synthetic-data-first posture. Real-PHI activation is gated behind signed agreements, compliance approval, and the backend security certification lane.

Real-PHI gate

The public launch posture is synthetic-data-first. Real client PHI is not accepted until agreements, compliance approval, and operational activation are complete.

Organization-aware design

The product is designed around organization boundaries, role scope, and review responsibility so enterprise evaluators can inspect how access should be separated.

Tamper-evident trail

Review activity is designed to produce a hash-chained history so changes can be checked during audit review.

Production validation

Cierta is deployed for controlled validation while infrastructure, restore, and security evidence remain in the backend certification lane.

Synthetic-data-first

The platform is developed and demonstrated on synthetic data. Real PHI is gated behind signed agreements and compliance controls.

Role-aware access model

Workspaces are organized around review roles, administrative scope, and compliance responsibility.

Audit defense, not capture

Designed to be defended

Cierta's workflow is oriented toward standing behind coding decisions in review. Supported findings are evidence-linked and MEAT-screened, submission stays behind human approval, and review actions are recorded so the question "why was this coded?" can be answered from the record.

  • Evidence linked to every finding
  • MEAT-style documentation screening
  • Human approval before any submission
  • Complete, tamper-evident action history
Compliance roadmap

Where we are, plainly

We believe security claims should be specific and honest. Current posture:

  • Today: production deployment for controlled validation under a synthetic-data-first posture
  • Real-PHI gate: real client PHI remains blocked until signed agreements, compliance approval, and operational activation are complete
  • Underway with counsel: business associate agreement, formal security documentation, and independent assessment

Evaluating Cierta for a regulated environment? Bring your security and compliance team; real-PHI use waits for the formal review path. Request a review →

Bring your security team

We'll walk through the product posture, activation gates, and compliance roadmap plainly.