Skip to main content
MaatFit

Trust & security

Built for healthcare-grade privacy, safety, and data residency — from the first line of code.

We believe transparency about what is true today, what is designed into the architecture, and what is on the roadmap is more useful than a list of certifications we haven't earned. Here is our honest account.

What is true today

Built. Tested. Real.

These are things we can say accurately about the platform as it stands today.

Privacy by design

PHI protection is built into the data architecture — not retrofitted. Patient information is stored encrypted, access is scoped to the treating physician, and data flows are designed with residency in mind.

Physician in command

No clinical decision is ever made without a physician. This is architectural: the system is built so that clinical outputs cannot reach a patient or a clinical record without physician review.

Deterministic safety layer

A rule-based safety system runs on every clinical step and cannot be bypassed by any user or by the AI. It is not probabilistic — the outcome is always the same for the same input.

No patient data for sale

We do not sell patient information. We never have. We are building audit mechanisms to make that verifiable over time.

Healthcare-grade security controls

Standard healthcare security controls — encryption in transit and at rest, scoped access, audit logging — are in place from the start, not scheduled for later.

Designed into the architecture

Not a compliance checkbox — a design principle.

These are architectural decisions baked into the system — not policies that could be changed without rebuilding.

Data residency

The platform keeps data in the region where care is delivered. In the United States today, data stays in the United States. International markets are designed to follow the same principle — in-region by default.

Physician-only clinical authority

The system is structured so that clinical outputs always pass through a physician before they affect patient care. This isn't a policy — it's an architectural constraint that the code enforces.

Minimal data collection

We collect only what is necessary for care. We don't collect health information on the early-access waitlist. We don't invite patients to enter clinical information until they are in active physician-led care.

Compliance roadmap

Where we're headed — honestly.

We are in early validation. The following certifications and audits are on our roadmap. We'll add them to this page as we earn them, not before.

  • HIPAA compliance framework — in design, targeted before any PHI is processed in production.

  • SOC 2 Type I/II — planned as a second-year milestone.

  • International data residency certifications — relevant to future international markets; designed into the architecture now.

We will not claim certifications we don't hold. When a certification is earned, it replaces this line.

Questions about security?

We take these questions seriously.

If you have specific questions about security, compliance, or data practices — as a physician, an organization, or an investor — we'll answer them directly.


MaatFit is a software platform for licensed clinicians and the organizations they work in. It does not provide medical advice and is not a substitute for professional medical care.

Trust & Security at MaatFit — MaatFit