generated: '2026-07-20' method: searched source: https://www.predoc.ai/security-compliance docs: https://www.predoc.ai/security-compliance standards: - id: fhir conforms: true evidence: "Platform delivers structured clinical data in FHIR-compliant format for EHR interoperability (predoc.ai/platform)." - id: hipaa conforms: true evidence: "HIPAA compliant; Business Associate Agreement (BAA) executed within 48 hours; administrative, physical, and technical safeguards in place." - id: soc2-type-2 conforms: true evidence: "SOC 2 Type II annual third-party audits against the Trust Services Criteria; report available under NDA." - id: fda-21-cfr-part-11 conforms: true evidence: "FDA 21 CFR Part 11 support for clinical research customers: complete audit trails for data access/modification and electronic signatures with authentication." - id: tls-1.3 conforms: true evidence: "TLS 1.3 in transit; AES-256 encryption at rest." - id: oauth2 conforms: false evidence: "Partner API uses JWT bearer tokens issued from a credential exchange, not an OAuth2 authorization-server flow." - id: rfc9457-problem-details conforms: false evidence: "Errors use a standard return object with status/message rather than application/problem+json." notes: >- Compliance posture captured from the published Security & Compliance page; standards conformance derived from the platform and Partner API documentation.