Compliance framework attestations, evidence pack summaries, and continuous monitoring status. All information on this page is public-safe — no secrets, keys, or internal configurations are exposed.
CUBE OneCare maintains alignment with major healthcare compliance frameworks. Evidence packs are available to customers under NDA.
Readiness maintained; report not issued
Security, Availability, and Confidentiality trust service criteria. Intended scope: all production infrastructure, application layer, and data processing pipelines.
Issued by: An independent CPA firm
Pre-audit complete; not yet certified
Information Security Management System (ISMS) covering software development, cloud operations, customer data handling, and third-party vendor management.
Issued by: An accredited certification body
Continuous — annual risk assessment
Administrative, physical, and technical safeguards for protected health information (PHI). CUBE has signed a BAA with Stedi (clearinghouse). BAAs with the rest of our providers, including hosting, are pending and will be published in the CUBE control panel when available. Until then, OneCare does not process real PHI.
Issued by: HIPAA has no certifying body
Pre-audit complete; not yet certified
Quality Management System covering software delivery lifecycle, customer support processes, and continuous improvement practices.
Issued by: An accredited certification body
Evidence is organized by control domain. Full evidence packs are available to auditors and enterprise customers under NDA via the Evidence vault.
| Control Domain | Evidence Items |
|---|---|
| Access Controls | RBAC policies, SSO configurations, MFA enforcement logs, privilege access reviews |
| Encryption | TLS certificate inventory, AES-256 key rotation records, encryption-at-rest attestation |
| Incident Response | IR playbooks, tabletop exercise reports, MTTR metrics, post-incident reviews |
| Change Management | CI/CD pipeline configs, deployment approvals, rollback procedures, code review policies |
| Vendor Management | Subprocessor registry, vendor risk assessments, DPA status, SOC 2 evidence from vendors |
| Business Continuity | BCP/DR plans, backup verification logs, RTO/RPO test results, failover documentation |
All governance policies are reviewed at least annually by the Information Security Committee. Last review dates are published for transparency.
Compliance is not a point-in-time exercise at CUBE OneCare. Automated controls continuously monitor infrastructure, application behaviour, and access patterns against our control framework.
Cloud configuration drift detection runs every 15 minutes. Non-compliant resources are auto-flagged and remediated.
Dependency scanning on every commit. Container image scanning on every build. Critical CVEs patched within 24 hours.
The HIPAA audit log is insert-only at the database with a 7-year retention policy. SHA-256 hash chaining and cryptographic verification are implemented in the enterprise audit-log module and are not enabled in the running product today.