
Yes, BastionGPT is engineered to support the requirements of both HIPAA and 42 CFR Part 2 for the handling of sensitive health information.
Yes, all of our plans automatically incorporate a BAA. You can review our BAA and related terms here. Where preferred, BAA's can be routed via Docusign for no additional cost.
Yes, sensitive data such as recordings and transcripts are encrypted using industry standard security measures such as TLS 1.2+) for data in transit and AES-256 for data at rest. Please note there are manual options to copy or download data to plaintext formats such as .mp4 and .txt files.
Data entered into BastionGPT is never sold or used for training AI models. BastionGPT makes no claim to any data that you provide.
Users have the ability to enter PHI into the system, where it will be transmitted and stored appropriately in line with HIPAA requirements.
BastionGPT provides the option to immediately delete specific items or all data at once. Data is maintained for up to 30 days in our secure audit vault to support required auditing, such as monitoring for illegal or prohibited system use. Custom data retention schedules will be releasing in early 2026.
Yes, our Enterprise plans support the use of your organization's existing Single Sign-On (SSO) and authentication platform. All other plans support email-based MFA with adaptive authentication.
Yes, customers with a USA billing address will store and process sensitive data within the USA. Sensitive data from customers with billing addresses in Canada or Australia will reside in their respective country.
Audit logs are maintained and monitored internally by our security team and can be requested ad-hoc as needed by the customer. Frequent audit log requests may incur administrative fees. Customers utilizing the Enterprise plans have access to automated data feeds if desired.
Yes, BastionGPT routinely performs internal and external (3rd party) penetration tests to validate our systems security.
BastionGPT exclusively operates on HITRUST CSF Certified and SOC 2 Type II attested infrastructure for all services processing, storing, or transmitting sensitive or confidential customer data, including all data submitted through the BastionGPT API and user interface. Our infrastructure providers maintain current certifications with annual audits.
Additionally, BastionGPT is pursuing its own HITRUST CSF Certification and SOC 2 Type II attestation. We are currently undergoing readiness activities, with no significant technical gaps observed to date. In the interim, we maintain comprehensive security controls aligned with HITRUST CSF and HIPAA requirements.
Yes, we maintain a documented incident response plan that is regularly reviewed and tested in accordance with industry best practices and compliance requirements.

Healthcare applications must stand up to the most sophisticated of attacks every day. BastionGPT was designed with security and privacy at its core, to ensure information stays safe from prying eyes and cyber threats.
“The role of penetration tests and code reviews in our security strategy can't be overstated. Our commitment to these proactive measures is our way of ensuring that our service is always a step ahead, ready to deal with potential vulnerabilities before they become actual threats.”
“During my testing process, I was impressed by the robustness and resilience of this application. BastionGPT is one of the most secure platforms I have tested.”