Skip to main content

Security overview for reviewers

SignalEDI is an AI-first EDI and API integration platform for small and mid-sized businesses that need fast, simple, affordable partner-mandate connectivity. Public security posture is limited to documented controls, readiness, policy links, system status, and a BAA review path. Review the current public paths at https://signaledi.com/trust.
Healthcare control readinessSOC 2 readinessReviewable logsTrust Center

Definition

SignalEDI
SignalEDI is an AI-first EDI and API integration platform for small and mid-sized businesses that need fast, simple, affordable partner-mandate connectivity. Security marketing pages summarize posture; your review should confirm controls against Trust Center documentation.

Key takeaways

  • Public security copy stays linked to Trust Center policies, status, and BAA review paths.
  • Healthcare and SOC 2 language stays at controls and readiness until current evidence authorizes a stronger claim.
  • Pair this overview with the Trust Center for encryption, logging, and subprocessor confirmation.

What reviewers ask about

Security signals in a scannable review grid

Healthcare control readiness

Healthcare control readiness covers data-handling architecture and reviewable operations; it is not a HIPAA certification claim.

Auditability

Role-based access and reviewable logs for regulated teams validating operational controls.

Operational transparency

Public status and clear trust narrative instead of invented uptime or volume claims.

Tenant separation

Customer workspaces stay scoped so partner data and account actions remain isolated during review.

Healthcare service scope · evidence reviewed 2026-08-05

Conditional means activated with evidence—not certified by default

This matrix describes the enforced product boundary. It is not an independent HIPAA, Part 2, SOC 2, or ISO attestation.

Service pathHIPAA42 CFR Part 2Enforced condition
SignalEDI core EDI processingCONDITIONALCONDITIONALHIPAA requires an executed BAA and tenant activation. Part 2 additionally requires counsel-approved agreement evidence, privileged approval, policy acknowledgement, partner classification, and consent provenance.
Inngest workflow orchestrationMETADATA_ONLYMETADATA_ONLYEvents may contain opaque job, gateway, tenant, and correlation references only; EDI and clinical payloads must remain server-side.
OpenAIPROHIBITEDPROHIBITEDNo PHI or Part 2 payload authorization is represented. Inputs use minimization and pattern-based redaction; suspected Part 2 content is denied before transmission.
AnthropicPROHIBITEDPROHIBITEDNo PHI or Part 2 payload authorization is represented. A corrective sub-processor notice is announced; suspected Part 2 content is denied before direct or failover transmission.
AWS Bedrock external model inferencePROHIBITEDPROHIBITEDNo PHI or Part 2 model-inference authorization is represented; suspected Part 2 content is denied before invocation.
External OCR and document capture providersPROHIBITEDPROHIBITEDHealthcare and suspected Part 2 documents remain blocked unless a separately reviewed, contracted, and technically authorized provider path is approved.
Marketing, analytics, outreach, and billing toolsPROHIBITEDPROHIBITEDCustomer EDI payloads, PHI, and Part 2 records are outside these service paths.

SignalEDI responsibilities

Enforce tenant, agreement, classification, consent, and provider gates fail-closed. Protect credentials and payloads with access controls, encryption, logging, and incident procedures. Maintain sub-processor disclosures, vendor assessments, and dated evidence for public claims.

Customer responsibilities

Determine whether HIPAA or 42 CFR Part 2 applies and classify source programs and trading partners accurately. Obtain and retain valid patient consent or another lawful authorization where required. Configure users, roles, retention, destinations, and downstream recipients consistently with the executed agreements.

Public diligence paths

Policies, status, and healthcare review in one path

Use these links during procurement, healthcare diligence, and developer review.

Security FAQ

How should we evaluate SignalEDI for healthcare data?

Healthcare control readiness covers data-handling architecture and reviewable operations; it is not a HIPAA certification claim. A BAA is available on any paid plan via the HIPAA/BAA add-on; Enterprise includes the add-on. An executed BAA is required before transmitting PHI. See /pricing for the published add-on rate.

What should a security reviewer read first?

Start at the Trust Center for policy links, public status, and the current narrative on controls. Ask for an evidence inventory when your review needs implementation-specific detail; this page does not promise a certification or private report.

How does SignalEDI approach audit logs?

Critical account, integration, and operational actions are designed to leave reviewable evidence for operators and security reviewers. Confirm exact retention and export behavior for the applicable plan and workflow during diligence.

Where do encryption details live?

Review transport, storage, key-management, and subprocessor statements in the current public security documentation during procurement.

Need a formal security review path?

Start with public artifacts, then contact sales when your healthcare, API, or procurement team needs implementation-specific detail.

© 2026 SignalEDI Inc. All rights reserved.