Sidepilot Technologies, Inc. | Trust Center
Sidepilot Trust Center
Welcome to Sidepilot's Trust Center. Here you can learn about our security practices, HIPAA compliance program, and request access to our security documentation.
Request documents

Resources

HIPAA Privacy Manual (Business Associate)

How Sidepilot uses, discloses and protects PHI as a HIPAA Business Associate.

Security Incident Response Plan

How we detect, contain, investigate and communicate security incidents.

Breach Notification Addendum

Our HIPAA breach assessment and notification procedures for covered-entity customers.

Information Security Policy

The security requirements that govern Sidepilot's people, systems and data.

Risk Assessment Policy

How we identify, rate and treat risks to customer data, including ePHI.

Vendor Management Policy

How we vet, contract with (including BAAs) and monitor vendors and subprocessors.

Data Classification Policy

How we classify data by sensitivity, with PHI treated as our most restricted class.

Data Retention and Disposal Addendum

How long we keep PHI and how we securely return or destroy it.

HIPAA Attestation: No Breach of Unsecured PHI

Signed attestation that Sidepilot has had no breach of unsecured protected health information.

FAQs

Yes. Sidepilot operates as a HIPAA Business Associate and signs a BAA with covered-entity customers before handling any protected health information (PHI) on their behalf.
Sidepilot is a cloud-based platform. Our application is hosted on Vercel and production data, including PHI, is stored in a managed Supabase database. Every provider that processes customer data is listed in the Subprocessors section below.
Yes. Data is encrypted in transit using TLS, and our hosting and database providers encrypt data at rest.
We have signed Business Associate Agreements with OpenAI and Twilio, our AI and communications providers. Our policy is to share PHI only with vendors that have signed a BAA with Sidepilot, and only after a documented risk review. All providers are listed as subprocessors below and are reviewed at least annually.
Access follows least privilege through role-based access controls and single sign-on. We review user access every quarter and remove access promptly when someone leaves or changes roles.
We follow a documented Security Incident Response Plan to contain, investigate and resolve incidents. If an incident involves your PHI, we notify you in line with our BAA and the HIPAA Breach Notification Rule.
Use the Request buttons in the Resources section above. Once your request is approved, you will get access to our HIPAA policies and related documents.
Email [email protected]. Our Security and Privacy Officer reviews every report.

Subprocessors

OpenAI

OpenAI is an artificial intelligence research and deployment company focused on building safe and beneficial "artificial general intelligence" (AGI).

Twilio

Twilio is a cloud-based communication platform that allows developers to add voice calls, text messages (SMS), email, and video into their software applications using APIs (Application Programming Interfaces).

Supabase

Managed Postgres database and backend services. Hosts Sidepilot's production application data.

Vercel

Cloud hosting and edge network for Sidepilot's web application.

Google Workspace

Email, identity (SSO) and document collaboration.

Monitoring

Continuously monitored by Secureframe

Compliance

HIPAA

Sidepilot operates as a HIPAA Business Associate. We maintain a HIPAA security and privacy program with documented policies, annual risk assessments, workforce training, vendor BAAs and continuous control monitoring through Secureframe.

Monitoring

Change Management

Change Management Policy
A Change Management Policy governs the documenting, tracking, testing, and approving of system, network, security, and infrastructure changes.
Configuration and Asset Management Policy
A Configuration and Asset Management Policy governs configurations for new sensitive systems
Segregation of Environments
Development, staging, and production environments are segregated.

Availability

Backup Restoration Testing
Backed-up data is restored to a non-production environment at least annually to validate the integrity of backups.
Testing the Business Continuity and Disaster Recovery Plan
The Business Continuity and Disaster Recovery Plan is periodically tested via tabletop exercises or equivalents. When necessary, Management makes changes to the Business Continuity and Disaster Recovery Plan based on the test results.
Business Continuity and Disaster Recovery Policy
Business Continuity and Disaster Recovery Policy governs required processes for restoring the service or supporting infrastructure after suffering a disaster or disruption.

Organizational Management

Security Awareness Training
Internal personnel complete annual training programs for information security to help them understand their obligations and responsibilities related to security.
Information Security Policy
An Information Security Policy establishes the security requirements for maintaining the security, confidentiality, integrity, and availability of applications, systems, infrastructure, and data.
Information Security Program Review
Management is responsible for the design, implementation, and management of the organization’s security policies and procedures. The policies and procedures are reviewed by management at least annually.

Confidentiality

Data Classification Policy
A Data Classification Policy details the security and handling protocols for sensitive data.
Disposal of Customer Data
Upon customer request, Company requires that data that is no longer needed from databases and other file stores is removed in accordance with agreed-upon customer requirements.
Data Retention and Disposal Policy
A Data Retention and Disposal Policy specifies how customer data is to be retained and disposed of based on compliance requirements and contractual obligations.

Vulnerability Management

Vulnerability and Patch Management Policy
A Vulnerability Management and Patch Management Policy outlines the processes to efficiently respond to identified vulnerabilities.

Incident Response

Lessons Learned
After any identified security incident has been resolved, management provides a "Lessons Learned" document to the team in order to continually improve security and operations.
Tracking a Security Incident
Identified incidents are documented, tracked, and analyzed according to the Incident Response Plan.
Incident Response Plan
An Incident Response Plan outlines the process of identifying, prioritizing, communicating, assigning and tracking confirmed incidents through to resolution.

Risk Assessment

Risk Assessment
Formal risk assessments are performed, which includes the identification of relevant internal and external threats related to security, availability, confidentiality, and fraud, and an analysis of risks associated with those threats.
Vendor Due Diligence Review
Vendor SOC 2 reports (or equivalent) are collected and reviewed on at least an annual basis.
Risk Register
A risk register is maintained, which records the risk mitigation strategies for identified risks, and the development or modification of controls consistent with the risk mitigation strategy.
Risk Assessment and Treatment Policy
A Risk Assessment and Treatment Policy governs the process for conducting risk assessments to account for threats, vulnerabilities, likelihood, and impact with respect to assets, team members, customers, vendors, suppliers, and partners. Risk tolerance and strategies are also defined in the policy.

Network Security

Network Security Policy
A Network Security Policy identifies the requirements for protecting information and systems within and across networks.
Endpoint Security
Company endpoints are managed and configured with a strong password policy, anti-virus, and hard drive encryption
Automated Alerting for Security Events
Alerting software is used to notify impacted teams of potential security events.

Access Security

User Access Reviews
System owners conduct scheduled user access reviews of production servers, databases, and applications to validate internal user access is commensurate with job responsibilities.
Access Control and Termination Policy
An Access Control and Termination Policy governs authentication and access to applicable systems, data, and networks.
Encryption-in-Transit
Service data transmitted over the internet is encrypted-in-transit.
Removal of Access
Upon termination or when internal personnel no longer require access, system access is removed, as applicable.
Encryption-at-Rest
Service data is encrypted-at-rest.
Encryption and Key Management Policy
An Encryption and Key Management Policy supports the secure encryption and decryption of app secrets, and governs the use of cryptographic controls.
Asset Inventory
A list of system assets, components, and respective owners are maintained and reviewed at least annually