Trust, stated plainly.
This page says what this site does, what we claim, and what we refuse to claim. Everything on it is checkable.
This page says what this site does, what we claim, and what we refuse to claim. Everything on it is checkable.
Waitlist entries (email, two fixed selections, a consent record); if you create one, an account; and if you use the inference API, key records and usage counts. This site runs no analytics and no tracking scripts. It sets one cookie, and only after you sign in: a session cookie. There are no advertising or cross-site tracking cookies. There are no third-party runtime origins, and fonts are self-hosted.
Vercel processes IP addresses and user agents in its own request and function logs under its retention policies. Those platform logs are separate from our waitlist records. We do not store your IP address in waitlist records. Details are in the privacy notice. Entries are stored in a private storage bucket on Vercel, our hosting platform, accessible to the PHIGate team and the deployment environment only.
Every quantitative or compliance-adjacent claim on this site lives in a claims registry with its evidence artifact, source, retrieval date, scope, and an expiry. The build fails if a claim's evidence is expired or missing. A date on this site is a content-review date, never a live system state.
If a claim is wrong, tell us: customerservice@healthit.com. We would rather publish a correction than defend an error.
There is no such thing as government HIPAA certification. HHS OCR does not endorse, certify, or recommend products, and we will never describe PHIGate or any listed model as certified or as inherently compliant. HHS OCR cloud guidance · 2026-07-16
PHI inputs are prohibited on every PHIGate surface, and we do not solicit PHI anywhere. That prohibition, not a technical barrier, is the Phase-0 boundary, and it is paired with a defined response if PHI reaches us anyway (below).
Under HHS guidance, a service that creates, receives, maintains, or transmits protected health information on behalf of a covered entity or business associate is itself a business associate, regardless of contracts, and a routing-and-logging gateway does not qualify for the transmission-only conduit exception.We are building toward operating as one properly, under signed agreements, with subcontractor agreements covering each upstream provider's eligible configurations. The BAA tier is in build and opens only when the agreements and controls that make it lawful exist. It has no launch date on this site.
If, despite the prohibition, PHI reaches a PHIGate surface, we have a defined response. If we become aware that a waitlist entry contains protected health information, we quarantine and delete it within 24 hours of becoming aware, and we keep a sanitized incident record containing no health information. Report suspected PHI to customerservice@healthit.com.
This site ships with HTTP security headers configured per OWASP cheat sheet guidance, including a content security policy with frame-ancestors denied, strict transport security, and a deny-by-default permissions policy. You can verify every header with curl. OWASP cheat sheets · 2026-07-16
The gateway threat model we are building is being organized against the OWASP Top 10 for LLM Applications 2025, scoped to the entries that apply to a gateway. The mapping will be published with the endpoint; we do not claim mitigations for entries that do not apply to a routing layer. OWASP GenAI Security Project · 2026-07-16
PHIGate's design is aligned with the NIST AI Risk Management Framework (AI RMF 1.0) and informed by its Generative AI Profile (NIST-AI-600-1). NIST operates no certification program and we claim no NIST certification, compliance, or approval. NIST AI RMF 1.0 · 2026-07-16
Within the Generative AI Profile's twelve risks, the honest gateway-layer fits are Data Privacy, Information Security, and Value Chain and Component Integration. We do not claim to mitigate content-level risks such as confabulation in routed models.
This site is designed to conform to WCAG 2.2 AA.
No government certification language, ever. No claim that merely transmitting data exempts a gateway from its obligations. No claim that PHI is technically blocked; an email field can carry anything, which is exactly why our forms have no narrative free-text fields and every one carries a warning. No model rankings or benchmark numbers until our protocol is final and publication rights are cleared. No uptime numbers without independent monitoring. If a sentence on this site fails adversarial reading, that is a defect. Report it.