Tundra Space

Tundra Space

Tundra Space Trust Center

Tundra Space protects clinical research data with HIPAA safeguards, encrypted infrastructure, private AI processing, and BAAs for organizations that submit PHI. Customer data is not used to train AI models.

Compliance

HIPAA Safeguards

Implemented

BAA for PHI Workflows

Available

Privacy-Forward AI

No training use

Encrypted Data

At rest and in transit

SOC 2 Type II

Planned

Controls

Tundra Space has implemented 0 security controls across 6 categories.

0

AI data privacy

No model training on customer data

User-submitted data, including prompts, uploaded documents, proprietary content, PHI, and AI outputs, is not used to train AI models.

Zero data retention model posture

AI providers are configured for zero data retention or equivalent no-retention processing where supported.

BAA required before PHI AI use

Organizations must execute a BAA with Tundra before submitting PHI to Regulatory AI or uploading PHI-bearing documents.

Security and stability telemetry only

Telemetry and analytics are limited to security, reliability, and stability signals. User-submitted data, including PHI, proprietary documents, prompts, and AI outputs, is private and not used for telemetry or analytics.

Access control

Unique user identification

Every user has a unique UUID. No shared accounts.

Role-based access control

Four-tier RBAC: owner, site_admin, admin, member.

Multi-factor authentication

TOTP-based 2FA via authenticator apps with backup codes.

Automatic session logoff

15-minute idle timeout with client-side warning.

Session revocation on password reset

All active sessions are invalidated when a password is changed.

Cryptographic protections

Encryption at rest (AES-256)

Database and object storage are encrypted via PlanetScale and AWS S3.

Encryption in transit (TLS 1.2+)

All connections enforce TLS. WebSockets use WSS.

Password hashing (bcrypt)

Passwords are salted and hashed. Plaintext is never stored.

Secure cookie attributes

HttpOnly, Secure, SameSite flags on all session cookies.

Audit and monitoring

Structured audit logging

All access events logged as structured JSON to CloudWatch.

6-year log retention

CloudWatch log groups configured for HIPAA-compliant retention.

Authentication event tracking

Sign-in, sign-out, failures, 2FA events, and password changes.

Document access audit trail

Database-level audit log for all document CRUD operations.

Business continuity

Automated database backups

PlanetScale point-in-time recovery with multi-AZ replication.

Object storage durability

AWS S3 with 99.999999999% (11 nines) durability.

Multi-availability zone deployment

Lambda and database deployed across multiple AZs.

Emergency access procedures

Documented procedures for emergency access with hardware MFA.

Organizational security

Designated Privacy Officer

Single point of responsibility for HIPAA compliance program.

Annual risk assessments

Formal risk analysis using NIST SP 800-30 methodology.

Workforce HIPAA training

Mandatory training within 30 days of hire, annual refresher.

Incident response plan

Documented procedures with 60-day breach notification timeline.

Business Associate Agreements

BAAs executed with all subprocessors that handle PHI.

Resources

Access Tundra Space's security documentation, compliance reports, and policies.

HIPAA Security Policy

Policy

Risk Assessment

Report

Incident Response Plan

Policy

Business Associate Agreement

Agreement

Employee Training Program

Policy

Contact security@tundraspace.com to request access to any document.

Subprocessors

Third-party services that process data on our behalf.

Service

Purpose

BAA

Amazon Web Services (AWS)

Cloud infrastructure, storage, compute, logging, and AWS Bedrock AI model hosting

Signed

PlanetScale

Production database hosting

Signed

Postmark

Transactional email (no PHI in emails)

N/A

OpenAI

No user-submitted data is sent to OpenAI

N/A

FAQ

Have security questions?

Reach out to discuss our security practices, request a BAA, or report a vulnerability.

security@tundraspace.com

Last updated March 2026

Reviewed annually