Built on a foundation health systems can audit.
UPP handles primary-source verified credentials, PHI-adjacent provider data, and signed attestations. Our security posture is designed for hospital procurement, payer infosec reviews, and NCQA delegated audits.
UPP is a Pre-Seed-stage company. This page documents the controls that are built into the product todayand the formal certifications that are on our funded roadmap. We have intentionally not claimed any audit, accreditation, or certification we have not actually completed. If a hospital or payer infosec team needs a particular control documented for a pilot, email security@myupp.us and we will respond with what we can substantiate.
Security controls
Need a security questionnaire response or a design-partner BAA?
We can respond to SIG-Lite, CAIQ, and HECVAT questionnaires today and will mark anything we cannot substantiate as not in scope at current stage rather than over-claim. SOC 2 Type I is a Pre-Seed milestone; BAA is a Seed-stage milestone gated on first paying design partner.

