Platform
Security & compliance posture
What's in place today for a healthcare/PHI-adjacent buyer, and what's on the roadmap — stated honestly.
Siphon targets healthcare CMMS/EAM data (the wedge), so a buyer's security review is a first-class concern. This page states the posture plainly: what's built, and what's in progress. No overclaiming.
Built today
- Encryption in transit & at rest. All source/destination credentials are envelope-encrypted (AES-256-GCM) with a KEK; plaintext secrets are never written to logs, the Restate journal, or the client bundle. TLS everywhere.
- Tenant isolation. Org → workspace → connection scoping is enforced in the service layer; an IDOR regression test proves cross-tenant reads are denied. Row-level security policies exist at the database layer (ADR-0013) as belt-and-suspenders.
- Least-data delivery. Bring-your-own-warehouse (BYO Postgres / SQL Server) keeps the buyer's data at rest in their own environment today — Siphon runs the pipeline and never holds their records.
- Auditability. An append-only audit log records spec publishes, connection changes, key rotations, and replays. Every sync run is inspectable (call timeline, quarantine, redacted request/response logging).
- Egress control. SSRF guard on outbound/destination connections (private/reserved address blocking). Per-connection rate limiting.
- Access control. Magic-link auth + per-workspace RBAC (ADR-0016); short-lived, connection-scoped embed tokens so a customer widget only ever sees its own connection.
- Data-tool posture. The internal agentic tooling defaults to local-first (ChunkHound, zero egress) and gates cloud tools on a data-handling review before they touch PHI-adjacent code.
In progress / required for a healthcare close
- HIPAA / BAA. A signed Business Associate Agreement is required before processing PHI. Asset + work-order data is often not PHI, but treat it as in-scope until confirmed. Status: BAA process to establish.
- SOC 2. Type II evidence assembly (access reviews, change management, monitoring, incident response). Status: scoping.
- RLS activation. The policies exist; enforcing them requires the app to connect as a
dedicated non-superuser DB role (a superuser bypasses RLS). Status: an ops
decision — provision the role + repoint
DATABASE_URL. - Penetration test + vulnerability management cadence. Status: planned.
- Self-hosted / BYOC compute. Running the entire stack (app, durable engine, database, KMS) inside your own AWS or GCP account — so execution as well as data stays in your environment — is fully designed (ADR-0008, ADR-0023–0027) and the key-custody core has landed, but the cloud KMS adapters, infrastructure modules, and installer are not yet built. Status: on the roadmap, not GA. Today, data-at-rest residency is available via BYO-warehouse.
For a security reviewer
Today, bring-your-own-warehouse keeps synced data at rest inside your own environment. Full self-hosted / BYOC compute — running execution in your own account — is designed and on the roadmap, not yet GA. Ask us for the current SOC 2 status and a BAA before sending PHI.