GUAVA COMPLIANCE FRAMEWORK
Guava adheres to six core pillars of compliance
We ensure that every one of our automations operate outside PHI boundaries while still maintaining rigorous enterprise-grade security, transparency, and auditability.
PILLAR | WHAT IT MEANS TO YOU | WHAT IT MEANS TO US |
---|---|---|
HIPAA Safe Harbor Alignment | We adhere strictly to HIPAA's de-identification and Safe Harbor principles | All ingestion and automation modules exclude the 18 protected identifiers defined under §164.514(b) |
SOC2 Mapped Controls | Internal security and change management processes follow SOC2 CC1-CC8 domains | Access logging, encryption, key rotation, and audit events are continuously monitored |
Data Minimization by Design | Guava processes only payer and policy data, not patient records | Every data path is validated against an allow-list schema before execution |
Zero Required EHR Connectivity | No EHR integration or PHI transfer | All workflows operate from structured payer documentation and administrator input only |
AI Governance & Human Oversight | Every agent action is logged and reviewable | Human-in-the-loop checkpoints ensure transparency and override capability |
Encryption & Integrity | Confidentiality and integrity throughout the lifecycle | AES-256 encryption for data at rest; SHA-256 hashing for integrity and detailed audit trails |
OUR COMMITMENT
Guava was built on a simple principle, which is that security and compliance are embedded and not added. Every one of our modules, APIs, and AI agents are built around data minimization and AI governance
For legal, information security, and procurement teams, we offer a detailed compliance packet including information on:
- SOC2 Control Mapping
- HIPAA Safe Harbor Attestation
- Our subprocessor DPAs
- Overview of our NLP and De-identification Architecture
- Summary of Data Retention and Access Policy
Contact security@guavamedical.ai for any and all inquiries. Include "Compliance Packet" in subject line to request a detailed authorized copy provided under NDA.