UPP
UPP
Universal Provider Passport
Trust Center

Built on a foundation health systems can audit.

UPP handles primary-source verified credentials, PHI-adjacent provider data, and signed attestations. Our security posture is designed for hospital procurement, payer infosec reviews, and NCQA delegated audits.

Stage disclosure

UPP is a Pre-Seed-stage company. This page documents the controls that are built into the product todayand the formal certifications that are on our funded roadmap. We have intentionally not claimed any audit, accreditation, or certification we have not actually completed. If a hospital or payer infosec team needs a particular control documented for a pilot, email security@myupp.us and we will respond with what we can substantiate.

Live
HIPAA-aligned controls
Architecture and operational controls are built to 45 CFR §164 from day one — encryption, access control, audit logging, BAA-ready vendor stack. A signed BAA with UPP is gated on first paying hospital design partner (Seed-stage milestone); we will not sign a BAA before we can stand behind every clause.
Roadmap
SOC 2 Type II
Pre-Seed today. Vanta/Drata-equivalent control monitoring is wired; the formal Type I audit kicks off at first SAFE close and the Type II observation window starts immediately after. Target Type II report: 12–14 months after Seed close. We do not claim an audit we have not started.
Roadmap
HITRUST CSF
Targeted post-Series A, once enterprise hospital and payer contracts justify the assessment cost. e1 essentials is the entry point.
Roadmap
NCQA Credentialing
NCQA Credentialing Accreditation application is the gating credential to win delegated credentialing contracts with health plans. Application targeted post-Seed, once we have 24 months of operating history NCQA requires.

Security controls

Encryption
AES-256 at rest (managed by our cloud database provider), TLS 1.3 in transit. Per-tenant envelope encryption for sensitive document payloads is wired in code today.
Access control
Row-level security enforced at the database layer for every public table. Role-based access (provider, hospital, payer, recruiter, admin) with org-scoped boundaries.
Data residency
Primary region us-east (managed Postgres). Daily encrypted backups with point-in-time recovery provided by the managed database tier.
Infrastructure
Edge-deployed on Cloudflare Workers; managed Postgres with private networking. No long-lived servers we have to patch by hand.
Audit trail
Every credential read, write, verification, and packet send is logged. Append-only retention policy will be locked to 7 years at SOC 2 Type I audit kickoff; today the data is retained without expiry.
Uptime
Inherits Cloudflare and managed-Postgres uptime SLAs. A 99.9% application-level SLA will be offered to hospital design partners; an enforceable multi-region failover is a Seed-stage milestone.

Need a security questionnaire response or a design-partner BAA?

We can respond to SIG-Lite, CAIQ, and HECVAT questionnaires today and will mark anything we cannot substantiate as not in scope at current stage rather than over-claim. SOC 2 Type I is a Pre-Seed milestone; BAA is a Seed-stage milestone gated on first paying design partner.