Skip to main content

Compliance

Built for HIPAA. Operating under SOC 2. Ready for 21 CFR Part 11.

How Synaptis meets the regulatory frameworks healthcare buyers ask about — and where each framework actually lands on the Synaptis platform.

Last reviewed:

Regulatory posture

  • HIPAA

    BAA available; controls operational

    All PHI processed via Synaptis platform

    Synaptis operates under HIPAA as a Business Associate. Signed BAAs available before any PHI is exchanged. Required Security Rule controls are operational and reviewed annually.

  • SOC 2 Type II

    Audit in progress — target Q4 2026

    Synaptis platform + AXIFI

    Type II audit underway. Trust Services Criteria covered: Security, Availability, Confidentiality. Type I available on request.

  • FDA 21 CFR Part 11

    Applied to AXIFI regulated-workflow surfaces

    Electronic records + electronic signatures in AXIFI clinical workflows

    Where AXIFI workflows produce records subject to Part 11 (e.g., clinical study workflows), the platform supports the required electronic signature, audit trail, and record integrity controls. Buyer's regulated-use determination drives the activation boundary.

  • GDPR

    Operational; DPA available

    EU data subject interactions

    Synaptis serves as data processor under GDPR for any EU data subjects routed through customer deployments. Standard contractual clauses + DPA available. Note: Synaptis is currently US-deployment-first; EU regional hosting available on request.

  • ISO 27001

    Policy framework documented; certification planned

    Management system

    We have an ISMS policy framework aligned to ISO 27001 controls. Certification is on the post-SOC 2 roadmap.

Cross-references

Most of the Security Rule and SOC 2 control families map directly onto controls documented under /trust/security. The compliance lens is who-audits-what; the security lens is how-it-works.