COMPLIANCE FIRST

Guava was built for enterprise healthcare systems, from the ground up.

Guava was designed to operate safely within the most rigorous hospital compliance regulations.

Our agents never require access to any EHR or identifiable patient information and are engineered to automate the entire prior authorization workflow outside the PHI boundary.

Learn more about our compliance frameworks.

DATA BOUNDARIES

Guava Subprocessors

Current as of

Know exactly where your data, as well as ours, goes and how it's being used. Below are Guava's subprocessors.

Your Data

No PHI accessed; Guava agents only pass publicly accessible payer policy facts and de-identified verdicts across the boundary.
FUNCTIONPURPOSELOCATION
Identity & Access ManagementUser authentication under hospital SSOOn premise; within hospital boundaries
Network SecurityEnsures all Guava connections originate and terminate within controlled boundariesOn premise; within hospital boundaries
PHI Regex GateEnsures any accidental input is containerized locally based on HIPAA Safe Harbor regexOn premise; within hospital boundaries
NLP De-IdentificationMedSpaCy local NLP model for on-premise final check in case of incidental inputOn premise; within hospital boundaries

Our Data

Guava's cloud and subprocessors guarantees automation without expanding your enterprise's regulatory surface.
NAMEPURPOSELOCATIONWEBSITE
GCSCloud infrastructure and hosting servicesUnited States
VercelFrontend hosting and developmentUnited States
AnthropicAI language model servicesUnited States
CartesiaSpeech-to-text and voice synthesisUnited States
PineconeVector database and searchUnited States
NeonServerless PostgreSQL databaseUnited States
OpenAIAI language model servicesUnited States
SlackTeam communication and notificationsUnited States
DeepgramSpeech-to-text and audio processingUnited States
SupabaseServerless PostgreSQL databaseUnited States
LiveKitReal-time AI voice agentsUnited States