Flume Health · Trust Center

Flume Health Trust Center

Trust center

Flume Health maintains a public trust center documenting SOC 2 Type II, HITRUST CSF, and HIPAA compliance.

HealthcareHealth PlansPayersHealthcare DataData IntegrationiPaaSEligibilityClaimsKnowledge GraphMCPagent-nativeAuthenticationData EngineeringInteroperability
Trust center: https://www.flumehealth.com/security

Certifications & Compliance

SOC 2 Type IIHITRUST CSFHIPAA

Source

Trust Center

Raw ↑
generated: '2026-08-16'
method: searched
probe: true
source: https://www.flumehealth.com/security
url: https://www.flumehealth.com/security
note: >-
  Flume Health names its compliance posture on a marketing security page. There is no trust portal, no evidence
  room, no auditor named, no attestation date, no report request flow, and no downloadable artifact behind any of
  the three claims — the page states them and stops. That is recorded faithfully below: `claimed`, not `verified`.
trust_portal: false
trust_portal_url: null
report_request_flow: false
certifications:
- name: SOC 2 Type II
  id: soc2-type-ii
  claimed: true
  verified: false
  evidence_url: https://www.flumehealth.com/security
  detail: Named on the public security page. No auditor, no report period, no attestation date, no report access flow.
- name: HITRUST CSF
  id: hitrust-csf
  claimed: true
  verified: false
  evidence_url: https://www.flumehealth.com/security
  detail: Named on the public security page. Certification level (e1/i1/r2) and validity dates not published.
- name: HIPAA
  id: hipaa
  claimed: partial
  verified: false
  evidence_url: https://www.flumehealth.com/security
  detail: >-
    The page says "HIPAA-aligned controls" — it does not claim certification (no such certification exists) and
    publishes no BAA, covered-entity/business-associate posture, or breach-notification commitment.
data_residency:
  claim: >-
    The platform is described on www.flumehealth.com as running on portable, customer-owned infrastructure —
    "your data never leaves your environment."
  evidence_url: https://www.flumehealth.com/
gaps:
- No trust center or evidence portal.
- No named auditor or attestation dates for SOC 2 or HITRUST.
- No subprocessor list published.
- No penetration-test summary published.
evidence:
- url: https://www.flumehealth.com/security
  http_status: 200
  keywords: [soc 2 type ii, hitrust csf, hipaa-aligned controls]
- url: https://www.flumehealth.com/trust
  http_status: 404
checked: '2026-08-16'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/flume-health-trust-center"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.