Security
Tenant isolation, MFA support, RBAC, audit logs, CSRF protection, CSP, and secure upload controls are part of the platform baseline.
Security overviewPointMintz is preparing for SOC2 Type I while keeping the current truth visible: product controls and evidence paths are built, HIPAA-covered signup is open with controls active, and formal compliance claims wait for completed evidence and auditor work.
Tenant isolation, MFA support, RBAC, audit logs, CSRF protection, CSP, and secure upload controls are part of the platform baseline.
Security overviewCustomer export, deletion, correction, processing restriction, DPA request flow, and sub-processor notice are wired into the product.
Privacy policyTenants can request the DPA package and review the processing, transfer, retention, and deletion summary before contract execution.
DPA summaryThe current vendor list covers hosting, communications, payments, DNS, and optional integrations, with material-change notice.
Vendor listReadiness controls, policy docs, risk register, vendor risk review, and evidence packet tooling are in place.
Readiness onlyHIPAA-covered self-serve signup is unlocked while category safeguards, consent, audit, encrypted clinical notes, and operational evidence controls remain active.
HIPAA readiness Signup unlocked