Trust Center

One hub for every question your auditor will ask.

This page is maintained by the MedIQ team to answer common security, privacy, and AI-governance questions about the platform. It reflects current capabilities and is not an independent certification.

Subprocessors

The third parties that touch MedIQ data.

MedIQ uses a small set of vetted infrastructure subprocessors. Each is covered by a BAA where PHI may transit. We notify customers in writing before adding a new subprocessor to a category that touches PHI.

SubprocessorPurposeRegionPHI?
Application hosting & edgeApplication runtime, edge deliveryUSNo (de-identified payloads)
Managed PostgresPrimary application databaseUSYes — under BAA
Object storageEncrypted documents, ERA filesUSYes — under BAA
Email (transactional)System emails, password reset, invitesUSNo
Error monitoringServer-side error capture (PHI-redacted)USNo
Managed AI gatewayGoverned AI inference; no names or member IDs, except card-scan images under BAAUSNo

Vendor names available under NDA. Enterprise customers receive the named subprocessor list as part of the security pack.

How we use AI safely

Managed by MedIQ. No tenant model choice.

MedIQ centrally vets, approves, and assigns AI models per task. Tenants never select models or hold third-party AI keys. Read the full governance design on theGoverned AI page.

No. MedIQ centrally vets, approves, and assigns models per AI task. Tenants never select models or hold third-party AI keys. Our operations team monitors performance and compliance and adjusts assignments for you.
Security & incident contact
Report a suspected vulnerability or security incident to security@cybergenai.com. We acknowledge within one business day.
Request security pack

Need a vendor security review?

We share our security overview, subprocessor list, and a draft BAA under NDA. Most reviews close in under a week.