DownStream

DownStream Security Trust Center

Security, privacy, compliance, and assurance information for customers and prospective customers evaluating DownStream.

Start your security review

Review public security and privacy information below, or request access to restricted materials available for customer and prospective-customer review.

Overview

Trust is earned in how we handle customer contracts, obligations, and evidence — and it is easy to lose.

The DownStream Trust Center provides security, privacy, compliance, and operational information for customers and prospective customers evaluating our platform.

Public policies are available directly below. Additional security materials may be made available to approved reviewers where appropriate.

DownStream is purpose-built for healthcare contractual intelligence and assurance. It is not currently intended to receive, store, or process PHI or ePHI, and DownStream does not currently offer a BAA for use of the platform with PHI.

Casey Morganelli

Founder and CEO, DownStream

Product Security

Controls that are in the product today. Items not listed here are not implied.

  • Role-based access control
  • Multifactor authentication
  • Tenant-isolated data access
  • Private document storage
  • Access logging
  • Idle session timeout
  • Account lockout controls
  • Minimum password length and compromised-password blocking
  • Secure development practices
  • Server-side secrets management
  • Human review before verification
  • No client-side AI keys
  • Separate privileged Admin Console with staff RBAC

Data Security

Customer documents and organization data are isolated by tenant and stored privately. Data stored by our infrastructure providers is protected using provider-supported encryption controls.

  • Encrypted connections in transit
  • Private customer-document storage
  • Tenant-isolated database access
  • Restricted access to customer documents by organization membership and role
  • Provider-supported encryption for stored data
  • Retention and deletion follow the customer agreement and organization settings
  • Not currently intended to receive, store, or process PHI or ePHI

Compliance & Frameworks

These are frameworks and regulatory areas our customers commonly evaluate or map against. Displaying a framework here does not represent certification or attestation unless specifically stated.

HIPAA

Reference / customer mapping

HITRUST

Reference / customer mapping

SOC 2

Audit planned

ISO 27001

Reference

NIST CSF

Reference

GDPR

Privacy consideration

Documents

Public policies open immediately. Requestable materials are provided after review. Planned items are not available yet.

Vulnerability Management

DownStream uses a layered vulnerability-management process across source code, dependencies, secrets, application security, and independent testing.

  • GitHub Dependabot for dependency alerts
  • GitHub CodeQL for static analysis
  • GitHub Secret Scanning
  • Vercel Web Application Firewall
  • Security advisories from infrastructure providers
  • Dynamic web application scanningPlanned
  • Independent third-party penetration testingPlanned

Business Continuity & Backups

DownStream relies on managed infrastructure and database providers with backup and recovery capabilities. Backup configuration and restoration procedures are maintained as part of our operational resilience program.

  • Supabase database backups
  • Vercel application deployment resilience
  • Documented recovery procedures
  • Backup restoration testingPlanned

AI & Data Processing

DownStream uses AI to assist with document analysis and structured extraction. AI-generated outputs are decision-support only and remain subject to human review before verification.

  • Document text may be processed by approved AI service providers when analysis runs
  • Customers control when analysis is run
  • AI keys stay on the server; they are not shipped to the browser
  • AI output is not treated as verified until a person reviews it

Risk Profile

A short view of how DownStream treats customer data and privileged access.

  • Customer data is logically isolated by organization
  • Customer documents are stored privately
  • DownStream is not currently intended for PHI or ePHI and does not currently offer a BAA
  • Public access to customer documents is not permitted by default
  • Approved subprocessors support hosting, authentication, AI processing, email, and billing
  • Restricted security materials are shared only through approved access

Reports / Assurance Materials

These are materials we can discuss with approved reviewers. A status of Planned means the artifact does not exist yet and is not available to download.

Current

  • Security OverviewAvailable on request
  • Architecture OverviewAvailable under NDA
  • Access Control ModelAvailable on request
  • Backup OverviewAvailable on request
  • Encryption OverviewAvailable on request

Planned

  • Third-Party Penetration Test SummaryPlanned
  • SOC 2 Type II ReportPlanned

Request restricted materials

Restricted security materials may be provided to current customers and qualified prospective customers after review. Certain materials may require NDA acceptance. Requests are not approved automatically.

Cookies

We use essential cookies to operate DownStream, including sign-in and security. Optional analytics cookies help us understand how the public website is used. Block all turns off optional cookies. Essential cookies still run because the site cannot work without them. See the Cookie Policy.