A real audit trail, not a marketing badge.
SOC 2 Type II compliant as of November 2024. Audit scope: Cloud Infrastructure & Data Handling.
ISO 27001 is in progress with target completion in Q4 2026.
AuthQuire extracts evidence, drafts packets, and maps payer requirements automatically, but final clinical approval, payer submission, and appeal decisions require human action.

What AuthQuire does — and does not do.
- Reads charts, orders, and prior imaging your team grants access to.
- Maps payer criteria to source evidence and flags missing items.
- Assembles versioned, source-cited packets ready for staff review.
- Drafts appeal letters and peer-to-peer briefs from chart evidence.
- Logs every read, change, approval, and export.
- Submit to payers automatically — staff approves and submits.
- Replace human authority: final clinical approval, payer submission, and appeal decisions require human action.
- Make clinical or medical-necessity decisions.
- Issue determinations or guarantee authorization outcomes.
- Move PHI to systems outside the customer-approved boundary.
- Train shared models on customer PHI.
How PHI is handled.
- BAA available
Business Associate Agreement signed with every customer handling PHI. Part of standard onboarding.
- PHI access controls
Roles include Admin, Reviewer, Read-Only (Billing), and System Auditor. MFA is mandatory for all user tiers, with Okta and Azure AD SSO support.
- Encryption
AES-256 at rest and TLS 1.2+ in transit. US-only data residency in AWS us-east-1.
- Audit logs
Audit logs cover data access events, PA packet modifications, and export events.
- Human approval
No packet leaves a workspace without a named reviewer's approval. Recorded on the receipt.
- Subprocessors
AWS (us-east-1) for hosting, Snowflake for analytics, and SendGrid for transactional email. Subprocessors handling PHI sign BAAs.
Every packet has a named reviewer.
No packet leaves AuthQuire without a recorded approval. The receipt below is the kind of trail your compliance team and payer auditors actually want to see.
- ReadChart pulled from connected EHR intake10:14
- MatchPayer criteria mapped (4 / 4 met)10:15
- EditReviewer added ROM measurements snippet10:17
- ApproveSarah M., reviewer — packet v310:18
- ExportPacket exported for staff submission10:19
What we claim — stated plainly.
- SOC 2 Type II
SOC 2 Type II compliant as of November 2024. Audit scope: Cloud Infrastructure & Data Handling.
- ISO 27001
ISO 27001 is in progress with target completion in Q4 2026.
- Encryption & residency
AES-256 at rest and TLS 1.2+ in transit. US-only data residency in AWS us-east-1.
- Model policy
Customer data is not used for global model training. Anonymized dataset improvements are opt-in only.
- BAA-supported workflows
AuthQuire executes a Business Associate Agreement with customers handling PHI before PHI moves into the workspace.
- No HIPAA certification
HIPAA does not issue certifications, so AuthQuire never describes itself as HIPAA certified. Security questionnaires are answered directly.
- Human authority boundary
AuthQuire extracts evidence, drafts packets, and maps payer requirements automatically, but final clinical approval, payer submission, and appeal decisions require human action.
- Confidence & escalation
Confidence scores below 0.85 trigger mandatory human review. Reviewers can override AI-mapped evidence; original extraction remains in version history.
- Retention & deletion
Clinical data retention is 7 years where required by HIPAA/state mandates; audit logs are retained for 3 years. Permanent erasure via cryptographic wipe upon contract termination with a 30-day recovery window.
Incident response and security contact.
Documented playbook covering detection, containment, customer notification, and remediation. Critical breach notifications are targeted within 24 hours; operational disruption notifications within 48 hours.
- Detect
- Contain
- Notify
Reach the AuthQuire security team for BAAs, vulnerability disclosures, or compliance questions:
security@authquire.com