Trust & security
A protection company should show you its own locks.
Here is how CuraDefend handles your information, stated plainly — including the honest maturity of our own young program.
No patient information, by architecture
CuraDefend assesses organizations, not patients. Forms warn against entering patient details, free-text is screened for obvious identifiers and quarantined when flagged, staff are trained to reject it during review, and nothing in the product asks for it. If patient information is ever discovered, we delete it and notify you.
Evidence without file hoarding
Our default verification model is look-don't-keep: a reviewer examines evidence over a controlled screen share and records a judgment, not your files. Document retention is disabled platform-wide by default; if it is ever enabled, uploads require explicit redaction confirmation.
Every account can carry MFA
All CuraDefend accounts support authenticator-app two-factor authentication, and internal CuraDefend staff accounts require it. Sessions are server-validated on every request; sensitive staff actions require recent re-authentication.
Tenant isolation, enforced server-side
Every data access is authorized on the server against your organization membership — never by anything the browser claims. Cross-tenant requests fail as not-found, and our automated tests attack exactly this boundary.
An append-only record
Consequential actions — decisions, overrides, verifications, report issuance — are written to an audit log that cannot be updated or deleted, enforced by the database itself. Issued reports are frozen the same way.
AI stays out of judgment
No AI system calculates scores, assigns severities, approves evidence, or determines anything about compliance. AI-assisted narrative drafting exists behind a flag that ships OFF, and customer evidence text is never sent to any AI provider.
Honest maturity statement
CuraDefend is an early-stage product operated by Psalm Wave LLC. We do not hold a SOC 2 attestation or HITRUST certification today, and we won’t imply otherwise with borrowed badges. What we can show is the architecture above, the audit trail inside the product, and a founder who reviews the work personally. As the company grows, third-party attestation is on the roadmap — and this page will say so plainly when it’s real.
Found a security issue? Email security@curadefend.com. We commit to acknowledging reports within two business days.
CuraDefend provides organizational risk, security, and compliance-support services. CuraDefend assessments and scores are informational risk-management tools and do not constitute legal advice, regulatory certification, or a guarantee of HIPAA compliance.