Skip to main content

Security overview for reviewers

SignalEDI is an EDI and API integration platform that gets suppliers ready for trading-partner mandates. Public security posture is limited to documented controls, HIPAA-compliant posture under an executed BAA, policy links, system status, and a BAA review path. Review the current public paths at https://signaledi.com/trust.
HIPAA CompliantSOC 2 Type IReviewable logsTrust Center

Definition

SignalEDI
SignalEDI is an EDI and API integration platform that gets suppliers ready for trading-partner mandates. Security marketing pages summarize posture; your review should confirm controls against Trust Center documentation.

Key takeaways

  • Public security copy stays linked to Trust Center policies, status, and BAA review paths.
  • SOC 2 Type I examination completed (report date June 19, 2026); Type II language stays out until a period examination authorizes it.
  • Pair this overview with the Trust Center for encryption, logging, and subprocessor confirmation.

What reviewers ask about

Security signals in a scannable review grid

HIPAA Compliant

SignalEDI supports HIPAA compliance for covered-entity and business-associate customers under an executed BAA: platform controls plus the HIPAA/BAA add-on path, with PHI only after BAA execution and tenant activation.

Auditability

Role-based access and reviewable logs for regulated teams validating operational controls.

Operational transparency

Public status and clear trust narrative instead of invented uptime or volume claims.

Tenant separation

Customer workspaces stay scoped so partner data and account actions remain isolated during review.

Independent examination · HIPAA posture

SOC 2 Type I examination completed, HIPAA Compliant

SOC 2 — examined 2026

SOC 2 Type I

SignalEDI completed an independent SOC 2 Type I examination (Johanson Group LLP). Report date: June 19, 2026. A Type I report describes controls at a point in time; it is not a Type II report over a period.

Report date: June 19, 2026

Trust Center →

HIPAA Compliant

HIPAA Compliant

SignalEDI supports HIPAA compliance for covered-entity and business-associate customers under an executed BAA. Platform controls plus the HIPAA/BAA add-on path; PHI only after BAA execution and tenant activation.

Trust Center →

Customers can request the full report under NDA on request. Request in your account → Trust Center →

Healthcare service scope · evidence reviewed 2026-08-05

Conditional means activated with evidence — PHI only after an executed BAA

This matrix describes the enforced product boundary for operating HIPAA-compliantly under an executed BAA. It is not a third-party examination report; suspected Part 2 content stays prohibited on external AI and analytics paths.

Service pathHIPAA42 CFR Part 2Enforced condition
SignalEDI core EDI processingCONDITIONALCONDITIONALHIPAA requires an executed BAA and tenant activation. Part 2 additionally requires counsel-approved agreement evidence, privileged approval, policy acknowledgement, partner classification, and consent provenance.
Inngest workflow orchestrationMETADATA_ONLYMETADATA_ONLYEvents may contain opaque job, gateway, tenant, and correlation references only; EDI and clinical payloads must remain server-side.
OpenAIPROHIBITEDPROHIBITEDNo PHI or Part 2 payload authorization is represented. Inputs use minimization and pattern-based redaction; suspected Part 2 content is denied before transmission.
AnthropicPROHIBITEDPROHIBITEDNo PHI or Part 2 payload authorization is represented. A corrective sub-processor notice is announced; suspected Part 2 content is denied before direct or failover transmission.
AWS Bedrock external model inferencePROHIBITEDPROHIBITEDNo PHI or Part 2 model-inference authorization is represented; suspected Part 2 content is denied before invocation.
External OCR and document capture providersPROHIBITEDPROHIBITEDHealthcare and suspected Part 2 documents remain blocked unless a separately reviewed, contracted, and technically authorized provider path is approved.
Marketing, analytics, outreach, and billing toolsPROHIBITEDPROHIBITEDCustomer EDI payloads, PHI, and Part 2 records are outside these service paths.

SignalEDI responsibilities

Enforce tenant, agreement, classification, consent, and provider gates fail-closed. Protect credentials and payloads with access controls, encryption, logging, and incident procedures. Maintain sub-processor disclosures, vendor assessments, and dated evidence for public claims.

Customer responsibilities

Determine whether HIPAA or 42 CFR Part 2 applies and classify source programs and trading partners accurately. Obtain and retain valid patient consent or another lawful authorization where required. Configure users, roles, retention, destinations, and downstream recipients consistently with the executed agreements.

Public diligence paths

Policies, status, and healthcare review in one path

Use these links during procurement, healthcare diligence, and developer review.

Security FAQ

How should we evaluate SignalEDI for healthcare data?

SignalEDI supports HIPAA compliance for covered-entity and business-associate customers under an executed BAA: platform controls plus the HIPAA/BAA add-on path, with PHI only after BAA execution and tenant activation. A BAA is available on any paid plan via the HIPAA/BAA add-on; Enterprise includes the add-on. An executed BAA is required before transmitting PHI. See /pricing for the published add-on rate.

What should a security reviewer read first?

Start at the Trust Center for policy links, public status, and the current narrative on controls. Ask for an evidence inventory when your review needs implementation-specific detail; this page does not promise a certification or private report.

What does the SOC 2 Type I examination cover?

SignalEDI completed an independent SOC 2 Type I examination (Johanson Group LLP). Report date: June 19, 2026. A Type I report describes controls at a point in time; it is not a Type II report over a period. Customers can request the full report under NDA on request — sign in to your account and open Help → Open a ticket (choose Compliance). Prospects who are not yet customers can email sales@signaledi.com. There is no public download.

How does SignalEDI approach audit logs?

Critical account, integration, and operational actions are designed to leave reviewable evidence for operators and security reviewers. Confirm exact retention and export behavior for the applicable plan and workflow during diligence.

Where do encryption details live?

Review transport, storage, key-management, and subprocessor statements in the current public security documentation during procurement.

Need a formal security review path?

Start with public artifacts, then contact sales when your healthcare, API, or procurement team needs implementation-specific detail.

© 2026 SignalEDI Inc. All rights reserved.