# Graphite Health > Graphite Health is a member-led, non-profit (501(c)(4)) health-data infrastructure > company founded by Intermountain Health, Presbyterian Healthcare Services and SSM > Health, with Kaiser Permanente and Emory Healthcare among its later members. It builds > a platform that ingests, standardizes and integrates clinical data across health > systems, and governs the S2 standard — an information standard encoding the operational > semantics of health data — together with a marketplace of applications certified under > its Digital Hippocratic Oath. ## Status of the developer surface (probed 2026-09-02) Graphite Health markets a developer platform — an SDK, a data sandbox, managed container runtimes and "standardized APIs" — but publishes NO public developer documentation and NO machine-readable contract. There is no OpenAPI, no GraphQL SDL, no AsyncAPI, no FHIR CapabilityStatement, no MCP server and no A2A agent card. /developers redirects (HTTP 308) to the marketing marketplace page, whose call to action is a contact form. The three API-shaped hosts that exist in DNS — fhir.graphitehealth.io, labs-core.graphitehealth.io and id.graphitehealth.io — all refuse TCP 443 from the public internet, so the platform is reachable only from inside member networks. Agents should treat Graphite Health as a contact-sales surface, not a callable one. ## Company - [Website](https://www.graphitehealth.io/): Graphite Health home - [Platform](https://www.graphitehealth.io/platform): ingestion, standardization, integration and AI-enablement of health data - [Marketplace / Ecosystem](https://www.graphitehealth.io/marketplace): the application ecosystem and Graphite Labs - [Health System Members](https://www.graphitehealth.io/members): the member health systems - [About](https://www.graphitehealth.io/about): mission and the non-profit model - [Team](https://www.graphitehealth.io/about/team): leadership, board and advisory board - [News](https://www.graphitehealth.io/news): announcements and press releases - [Careers](https://www.graphitehealth.io/careers): open roles - [Contact](https://www.graphitehealth.io/contact): the only intake path for platform, marketplace and security enquiries ## Trust, security and compliance - [Trust & Security](https://www.graphitehealth.io/about/trust-security): SSAE 18 SOC 2 Type 1 certified; SOC 2 Type 2 in progress; NIST SP 800-218 SSDF adopted; responsible-disclosure program with discretionary bug bounty - [Terms of Use](https://www.graphitehealth.io/terms-of-use) - [Privacy Policy](https://www.graphitehealth.io/privacy) ## Standards - [S2 standard](https://www.graphitehealth.io/news/gates-ventures-propel-adoption-graphite-health-s2-standard): Graphite's information standard for the operational semantics of health data, adoption funded by Gates Ventures. Announced and described, but the specification is not published at any public URL. - Digital Hippocratic Oath (DHO): Graphite's ethics certification, required of member systems and of every marketplace application. - openEHR lineage: Thomas Beale, principal author of the openEHR Reference Model and Archetype specifications, is on the Graphite team. No openEHR archetypes, templates, CKM instance or AQL endpoint are published. - FHIR: named in platform positioning ("standard-based APIs using common interoperability standards, such as FHIR"), unverifiable — fhir.graphitehealth.io does not answer. ## Code - [GitHub organization](https://github.com/graphitehealth): 5 public repositories, all forks of third-party projects. No first-party source, no client SDK in any public package registry. ## API Evangelist artifacts - [apis.yml](https://raw.githubusercontent.com/api-evangelist/graphitehealth/refs/heads/main/apis.yml): the APIs.json profile for Graphite Health - [Conformance](https://raw.githubusercontent.com/api-evangelist/graphitehealth/refs/heads/main/conformance/graphitehealth-conformance.yml): standards and compliance claims with evidence - [Trust center](https://raw.githubusercontent.com/api-evangelist/graphitehealth/refs/heads/main/security/graphitehealth-trust-center.yml) - [Vulnerability disclosure](https://raw.githubusercontent.com/api-evangelist/graphitehealth/refs/heads/main/security/graphitehealth-vulnerability-disclosure.yml) - [Domain security](https://raw.githubusercontent.com/api-evangelist/graphitehealth/refs/heads/main/security/graphitehealth-domain-security.yml): TLS 1.3, HSTS 2y, DNSSEC signed, SPF and DMARC present (p=none), no CAA - [Well-known probe](https://raw.githubusercontent.com/api-evangelist/graphitehealth/refs/heads/main/well-known/graphitehealth-well-known.yml): every named path 404 - [Packages](https://raw.githubusercontent.com/api-evangelist/graphitehealth/refs/heads/main/packages/graphitehealth-packages.yml): registry sweep, zero first-party libraries - [Plans](https://raw.githubusercontent.com/api-evangelist/graphitehealth/refs/heads/main/plans/graphitehealth-plans-pricing.yml): no published pricing; membership model - [Rate limits](https://raw.githubusercontent.com/api-evangelist/graphitehealth/refs/heads/main/rate-limits/graphitehealth-rate-limits.yml): none documented