Security & compliance
Can this platform hold PHI inside our control environment?
Controls in place today, the exact documents vendor risk receives, and the current audit posture. SeniorCRE does not claim SOC 2 certification or its own SOC 2 report; no completed independent penetration-test report is claimed.
Canonical page: /security-architectureMutual non-disclosure agreement
DownloadTwo-year Texas-governed mutual NDA that unlocks the diligence documents below.
DownloadBusiness Associate Agreement (template)
DownloadHIPAA BAA template for covered entities, including downstream sub-processor flow-down.
DownloadMaster platform agreement (template)
DownloadCommercial and data-handling terms, including export and termination obligations.
DownloadEmployee confidentiality, IP & data hygiene (template)
DownloadPersonnel-side controls: confidentiality, device hygiene, and PHI handling duties.
DownloadSecurity architecture overview
Published pageTenancy model, Row-Level Security posture, encryption, audit logging, access control.
Read the positionSIG Lite / CAIQ v4 responses
On request under NDAPre-populated questionnaire responses mapped to current controls.
Requested from support@seniorcre.com after the mutual NDA is executed.
Incident response and business continuity runbooks
In draftDetection, triage, containment, notification, RTO/RPO drill plan. Ratified before pilot go-live.
Authored, not yet ratified. Finalized before pilot go-live — we will not back-date a runbook to look ready.