Authenticx · Trust Center

Authenticx Trust Center

Trust center

Authenticx maintains a public trust center documenting SOC 2 Type I & II, HIPAA, GDPR, and CCPA compliance.

conversation-intelligencehealthcarespeech-analyticscontact-centercustomer-experiencequality-assurancepharmacovigilancepatient-experiencetranscriptionlife-sciencesscimoauth2
Trust center: https://authenticx.com/privacy-security

Certifications & Compliance

SOC 2 Type I & IIHIPAAGDPRCCPA

Source

Trust Center

Raw ↑
generated: '2026-08-14'
method: searched
probe: true
url: https://authenticx.com/privacy-security
title: 'Privacy & Security — Built for healthcare. Secured for trust.'
kind: security-and-compliance-page
dedicated_trust_portal: false
certifications:
- name: SOC 2 Type I & II
  body: AICPA
  quote: 'SOC 2 Type I & II — AICPA'
  evidence_url: https://authenticx.com/privacy-security
- name: HIPAA
  body: HHS (US)
  quote: 'HIPAA — HIPAA Compliant'
  kind: regulatory-compliance-claim
  evidence_url: https://authenticx.com/privacy-security
- name: GDPR
  body: EU / UK
  quote: 'GDPR — General Data Protection Regulation (EU & UK)'
  kind: regulatory-compliance-claim
  evidence_url: https://authenticx.com/privacy-security
- name: CCPA
  body: State of California
  quote: 'CCPA — California Consumer Privacy Act'
  kind: regulatory-compliance-claim
  evidence_url: https://authenticx.com/privacy-security
not_claimed:
- HITRUST CSF
- ISO 27001
- ISO 27017
- ISO 27018
- PCI DSS
- FedRAMP
- CSA STAR
- 'NIST 800-53'
controls_published:
- area: Access Management
  controls:
  - name: Role-Based Access Controls
    detail: >-
      Each client operates in a dedicated resource group with least-privilege access controls, while Azure AD
      securely manages user identities and role-based permissions.
  - name: Single Sign-On (SSO) & Identity Management
    detail: >-
      Authenticx enforces multi-factor authentication for internal services and supports Single Sign-On (SSO),
      requiring unique credentials for each authorized user.
  - name: Application Governance & Audit Logging
    detail: >-
      Governance policies are applied to cloud infrastructure and APIs, with comprehensive audit logs tracking
      access, authentication attempts and data activity within sensitive systems.
- area: Quality Assurance & Change Management
  controls:
  - name: Personnel
    detail: >-
      Background checks, ongoing security training for all employees, and documented policies and procedures
      governing risk management and incident response.
  - name: Auditability & Monitoring
    detail: System activity is logged and monitored for transparency, traceability and accountability.
  - name: Continuous Improvement
    detail: Controls are continuously evaluated and refined against healthcare and regulatory standards.
- area: Data Resiliency
  controls:
  - name: Data Back-Up
    detail: Encrypted daily backups of customer and system data, with production-equivalent protections.
  - name: Data Storage
    detail: >-
      Hosted across multiple data centers with built-in failover, on Azure infrastructure engineered for
      99%+ data durability and continuity.
  - name: Disaster Recovery
    detail: Annual disaster recovery and backup restoration testing.
- area: Data Protection
  controls:
  - name: Purpose Limitations
    detail: >-
      "Data is processed solely to deliver conversation intelligence insights for your organization.
      Sensitive healthcare data is never sold or used to train our models."
  - name: Data Minimization
    detail: Only the data necessary to deliver the service is collected and retained.
gaps:
  vulnerability_disclosure: false
  security_contact: false
  bug_bounty: false
  security_txt: false
  pen_test_statement: false
  subprocessor_list: false
  audit_report_request_flow: false
  note: >-
    The page is a marketing-tier trust statement, not a trust CENTER: there is no portal to request the SOC 2
    report, no subprocessor list, no named security contact, no responsible-disclosure or bug-bounty program,
    no /.well-known/security.txt (404 on authenticx.com, 403 default-deny on api.beauthenticx.com), and no
    penetration-testing statement. trust.authenticx.com and security.authenticx.com do not resolve. A
    healthcare buyer's security review therefore starts with an email, not a document.
evidence:
- source: https://authenticx.com/privacy-security
  status: 200
  keywords:
  - soc 2 type i & ii
  - hipaa compliant
  - gdpr
  - ccpa
  - encrypted daily backups
  - audit logging
  fetched: '2026-08-14'
probes:
- url: https://trust.authenticx.com/
  status: '000'
  note: does not resolve
- url: https://security.authenticx.com/
  status: '000'
  note: does not resolve
- url: https://authenticx.com/security
  status: 404
- url: https://authenticx.com/.well-known/security.txt
  status: 404
- url: https://authenticx.com/privacy-security
  status: 200
related:
- conformance/authenticx-conformance.yml
- security/authenticx-domain-security.yml