SOC 2 Type II
Certified · 2024
Annual audit completed with zero exceptions. Comprehensive security, availability, processing integrity, confidentiality, and privacy controls verified.
Trust Center
Healthcare buyers trust QuickIntell for SOC 2 Type II certified, HIPAA compliant infrastructure
Procurement TLDR
Trusted by healthcare organizations nationwide
† No HIPAA breach reports filed. See the SOC 2 Type II attestation cover page (available under NDA).
Certified · 2024
Annual audit completed with zero exceptions. Comprehensive security, availability, processing integrity, confidentiality, and privacy controls verified.
Certified · 2024
Information Security Management System certification. Demonstrates commitment to highest standards of information security including confidentiality, integrity, and availability of data.
Compliant
Business Associate Agreements (BAA) available for all covered entities. Full compliance with HIPAA Privacy and Security Rules.
Program memberships are not security certifications or audit results.
Member
AI startup accelerator program
About NVIDIA Inception (opens in a new tab)Partner
Enterprise-grade cloud infrastructure
About Microsoft for Startups (opens in a new tab)QuickIntell is ready to execute a Business Associate Agreement with all covered entities. Request your BAA in minutes with our streamlined process.
At QuickIntell, protecting healthcare and customer data is our top priority. Our Managing Director personally leads security initiatives, ensuring that data protection is prioritized across all teams and embedded into every process we follow.

QuickIntell is ISO 27001:2022 certified, reflecting our commitment to the highest standards of information security, including confidentiality, integrity, and availability of data. Our certification is available upon request for clients and partners seeking verification.
Top-down security leadership ensures data protection is embedded in every process.
Regular audits and assessments ensure our security posture evolves with emerging threats.
Designed specifically for healthcare organizations with HIPAA and SOC 2 compliance.
QuickIntell implements comprehensive data protection measures to safeguard Protected Health Information (PHI) and customer data in compliance with HIPAA and healthcare privacy obligations.
PHI for U.S. healthcare customers is stored in U.S.-based cloud services (AWS, Azure, GCP) with enterprise-grade security protocols. Tenant, workload, and agreement controls govern non-PHI business data residency.
QuickRCM supports HIPAA-aligned handling with Business Associate Agreements (BAA) available for covered entities. Privacy requests are handled through contract, retention, and healthcare compliance workflows.
Configurable record retention periods give clients control over regulated data lifecycles, including 90-day unpinned AI Assistant thread purge and 7-year audit evidence retention where applicable.

Multi-layered security controls protect your healthcare data at every stage of processing, storage, and transmission.
Beyond infrastructure and policy, QuickIntell ships hard guardrails inside the product itself — so PHI handling, agent autonomy, and outbound voice stay safe by default, not by checklist.
Sensitive actions, permission changes, exports, configuration edits, and automation decisions are written to append-only audit logs retained for at least 7 years by default for compliance evidence.
Every operational record carries an organization identifier, and queries filter by that tenant boundary so cross-organization access is blocked at the data layer.
Agent memory remains organization scoped, unpinned threads purge after 90 days, and semantic recall over old messages is disabled to prevent PHI from being retrieved by inference.
Portal and EHR credentials are encrypted at rest in AWS Secrets Manager, scoped to the customer organization, and fetched only into ephemeral session memory when an authorized task runs.
Write actions and customer-configured high-impact automations use approval gates before changes are committed. QuickVoice contact workflows can run automatic, semi-automatic, or approval-backed based on customer policy, with execution metadata logged without PHI values.
QuickVoice recordings and transcripts stay encrypted and tenant scoped. Listening requires voice access, while transcript export requires the separate voice recording export permission.
Outbound voice and collections workflows check DNC opt-outs, TCPA quiet hours in the patient's local time, FDCPA Reg F frequency limits, and state restrictions before contact attempts are allowed.

Hosted on AWS, Microsoft Azure, and Google Cloud Platform for high availability, redundancy, and global CDN distribution.
99.9% uptime SLA with auto-scaling, continuous functional monitoring, and automated backup systems for business continuity.
Data centers maintain physical security, key management, redundancy, and disaster recovery procedures.
Access comprehensive security documentation, compliance reports, and legal agreements. Enterprise customers can request NDA-protected documents including SOC 2 reports and penetration testing results.
Complete audit report covering security, availability, processing integrity, confidentiality, and privacy controls.
Summary of HIPAA compliance measures, administrative safeguards, physical safeguards, and technical safeguards.
Standard BAA template available for covered entities. One-click request for custom BAA execution.
GDPR-compliant DPA for international prospects. Standard template available for review and execution.
Contact for DetailsComprehensive overview of encryption standards (at rest/in transit), access controls, audit trails, and incident response procedures.
Annual third-party penetration testing summary. Latest assessment completed with remediation tracking.
Detailed information about where data is stored, which cloud providers are used, and data sovereignty options.
Contact for DetailsComplete list of third-party sub-processors, their locations, and data processing activities.
QuickIntell maintains data in secure, compliant cloud regions with full transparency about data location and processing activities.
Comprehensive security controls and continuous monitoring to protect your healthcare data. All security measures are independently audited and continuously monitored.
QuickIntell continuously monitors compliance status and security controls. Enterprise customers get exclusive access to our trust portal powered by industry-leading compliance automation platforms.
Real-time dashboard showing SOC 2 and HIPAA compliance status
24/7 security monitoring results, vulnerability assessments, and threat detection
Up-to-date list of all third-party sub-processors with locations and data processing activities
Automated completion of security questionnaires (SIG, CAIQ, VSA) for faster procurement
Trust Portal Powered By:
Compliance status and security metrics updated in real-time, no manual refresh needed.
SSO-enabled portal with role-based access controls for your security team.
Pre-filled security questionnaires reduce procurement time by up to 80%.
We partner with selected sub-processors to enhance product functionality while maintaining high security standards. All sub-processors are contractually required to meet our security and compliance requirements.
| Sub-processor | Processing Scope | Activity | Data Type |
|---|---|---|---|
| Google Cloud | U.S. region for PHI | Hosting/storage | Infrastructure & storage |
| Amazon Web Services (AWS) | U.S. East, U.S. West | Hosting/storage | Infrastructure & storage |
| Microsoft Azure | U.S. East, U.S. West | Hosting/storage | Infrastructure & storage |
| Customer.io | Non-PHI communications | Email marketing | Communication data |
| Hubspot | Non-PHI CRM | CRM/email | Customer data |
| MailerSend | Non-PHI transactional email | Transactional email | Communication data |
| Chameleon | Non-PHI in-app guidance | In-app guides | User interaction data |
| Telnyx | Contracted QuickVoice telephony | Call routing and phone services | Telephony metadata and audio transport |
| Stripe | Payment data only | Payment processing | Financial data |
Protected Health Information stays on U.S.-based infrastructure: AWS (U.S. East/West), Microsoft Azure (U.S. East/West), and Google Cloud (U.S. region). QuickRCM records, QuickVoice recordings and transcripts, and AI Assistant threads are encrypted and tenant scoped under those residency controls. Stripe processes billing/financial data only and does not receive PHI.
Customer.io, Hubspot, MailerSend, and Chameleonreceive only product, marketing, and in-app guidance data (work email, account, usage events). They are never sent Protected Health Information from the QuickIntell application.
For the full residency policy and product control details, see the data-residency FAQ entry below.
Powers speech-to-text recognition, medical transcription, clinical documentation, and content summarization in our healthcare AI solutions.
All data is stored on US-based servers (AWS, Azure, GCP) under enterprise-grade security protocols with encryption at rest and in transit.
No customer data or PHI is used to train AI models, ensuring full confidentiality and compliance with healthcare privacy regulations.

We welcome reports from security researchers and the broader community. Responsible disclosure helps us protect the healthcare organizations and patients who rely on QuickIntell. We follow the guidance set out in RFC 9116 for publishing security contact information.
Email our security team with reproduction steps, affected endpoints, and any supporting evidence. We aim to acknowledge reports within two business days.
security@quickintell.comOur machine-readable security contact file is published at the well-known URI defined by RFC 9116.
View /.well-known/security.txtPGP key publication is in progress. Until a verified public key and fingerprint are published, send sensitive disclosures to security@quickintell.com and avoid including PHI, credentials, or unnecessary exploit details in the initial report.
PGP Key Status
Not yet published. We will mirror the public key and verified fingerprint here and in our security.txt file before asking researchers to encrypt with PGP.
Researchers who act in good faith, avoid privacy violations, and follow coordinated disclosure timelines will not be subject to legal action by QuickIntell. Please do not access, modify, or exfiltrate Protected Health Information (PHI) while testing.
Find answers to common questions about QuickIntell's security practices, compliance certifications, and data protection measures.
Join healthcare organizations that trust QuickIntell with their sensitive data and security requirements. Get started with a free demo today.
Direct review links: BAA, SOC 2 report, Sub-processors, Incident response, AI data handling, Vulnerability disclosure. Security researchers and assurance teams can also review our /.well-known/security.txt contact file or check our real-time status dashboard.