Fly.io, Inc.
- Purpose
- Primary infrastructure — compute, managed Postgres, managed key-value store, automated backups
- Region
- United States (Virginia)
- DPA
- No DPA or BAA recorded in annex
CUBE OneCare’s security posture, compliance frameworks, sub-processors, and key controls — all in one place. We publish because transparency is a feature.
Which frameworks CUBE is aligned with, and why it is certified under none of them
Health Insurance Portability and Accountability Act
All three safeguard categories documented and operating: Administrative (§164.308), Physical (§164.310), and Technical (§164.312). CUBE has signed a BAA with Stedi (clearinghouse). BAAs with the rest of our providers, including hosting, are pending and will be published in the CUBE control panel when available. Until then, OneCare does not process real PHI.
Service Organization Control — All 5 Trust Service Criteria
All five TSC (Security, Availability, Processing Integrity, Confidentiality, Privacy) are mapped with readiness evidence. External report status is represented only when issued.
Information Security Management System
Annex A controls are mapped and assessed against the current ISMS scope. Internal audit and management review evidence are maintained for auditor review.
Health Information Trust Alliance Common Security Framework
HITRUST CSF r2 control mapping completed. bC (Basic Current) assessment not yet scoped.
General Data Protection Regulation (EU) 2016/679
Article 28 DPA terms are available for enterprise agreements. Retention schedules are defined in policy. Where a transfer safeguard is required, it is agreed and executed in the contract before the transfer. No Data Protection Officer has been formally appointed.
California Consumer Privacy Act & California Privacy Rights Act
Opt-out rights, data deletion, and data portability supported. Privacy policy updated to reflect CPRA amendments.
The controls that carry the most weight, and how each is enforced
AES-256 at rest · TLS 1.3 in transit
PHI access audit log, insert-only at the database · 7-year retention policy
Fly.io PaaS · US region · 99.9% uptime target
No third-party penetration-test report available today
RBAC + MFA enforced for all staff
Structured application logging · error monitoring with automated alerts
15-min idle timeout · httpOnly cookies
RPO < 1 hour · RTO < 4 hours · tested biannually
Third-party services that may have access to customer data. Individual DPA or BAA status is shown per row from the legal annex; it is not assumed for every vendor. Large healthcare institutions that require a dedicated, compliance-hardened environment may request a separately scoped white-label infrastructure option, contracted separately.
This list is updated within 30 days of any sub-processor change. To object to a new sub-processor, contact contact the privacy team.
CUBE OneCare is aligned with HIPAA as a platform. Processing PHI requires a Business Associate Agreement executed directly with the client. CUBE's own Business Associate Agreement with its infrastructure hosting provider has not yet been executed; no PHI is processed on that hosting platform until it is.
How to report a vulnerability, and what happens after you do
Pre-filled responses for CAIQ, SIG Lite, and custom security intake forms. Returned within 5 business days.
Request questionnaireControls documentation and incident response plans. Audit evidence is shared under NDA through the secure compliance contact form.
Request under NDAData Processing Agreement (GDPR) available on request. CUBE has signed a BAA with Stedi (clearinghouse). BAAs with the rest of our providers, including hosting, are pending and will be published in the CUBE control panel when available. Until then, OneCare does not process real PHI.
Request agreementFor ISO 27001 ISMS, ISO 9001 QMS, control mapping, shared responsibility, governance, and evidence vault documentation.
Security & Compliance