Trust & security

Built to clear your security review.

Encryption, immutable audit, PII/PHI governance, and data residency — shipped and configurable per organization. Agreements (DPA + SCCs, BAA on request) and our full posture live on the compliance page.

Conduix's governance is auditable, defense-in-depth — it reduces provider exposure; it is not a HIPAA compliance program or a substitute for a BAA.

Enterprise controls, shipped

Full compliance posture
  • Immutable audit log
  • Policy enforcement
  • PII / PHI governance
  • Encryption at rest
  • SSO / SAML
  • Hard spend caps

Security practices

How we protect your data

Every control below is configurable per organization, and every change is written to your audit log.

Encryption

Provider secrets encrypted at rest with AES-256-GCM; TLS 1.2+ in transit.

API key handling

Keys are hashed, never stored in plaintext, and shown once at creation.

PII & PHI governance

Detect and tokenize structured PII; pin PHI to approved providers, fail-closed.

Immutable audit

Every request, key action, and policy change — append-only and exportable.

Data residency

Pin processing to US, EU, or APAC regions at the router.

Secret detection

Detected credentials trigger a rotation advisory before they reach a provider.

Structured PII only (not names, addresses, or free-text). See the governance docs for exact routing and audit behavior.

Everything procurement needs, in one place.

Certifications, sub-processors, and DPA/SCCs — request agreements or a security package from our team. HIPAA/BAA support is in development.