GCC/Compliance & Security

The hard part of any healthcare GCC — owned.

For procurement and security reviewers: this is how we handle HIPAA, BAAs, data, identity, and audit. Not a posture we promise to build — one we already run for a live US healthcare product.

HIPAA controls in production BAA before any access SOC 2 underway Zero-trust posture

HIPAA controls

Administrative, physical, and technical safeguards implemented and maintained — the same controls behind our own product.

BAA before access

A Business Associate Agreement is executed before any team member touches protected health information. No exceptions.

SOC 2 underway

A formal SOC 2 program is in progress, building on the controls already operating in production.

Data-handling SOPs

Documented standard operating procedures for data classification, storage, transit, and disposal — auditable end to end.

Access & identity governance

Least-privilege access, role-based controls, and identity governance across every environment your team touches.

Zero-trust posture

Security-by-design, not security-by-afterthought — verification at every boundary, with audit-ready documentation.

For your security review

We're built to pass procurement and security diligence — because we've passed it ourselves, with paying US healthcare clients. Request our compliance overview and we'll walk your reviewers through controls, evidence, and the BAA process.

FAQ

Compliance, answered.

When is the BAA executed?
Before any access to protected health information — it is a precondition of work beginning, not a follow-up. Identity provisioning and the BAA are part of mobilization.
Are these controls aspirational or real?
Real and in production. The posture described here is the same one operating behind DocuFindr, a live US healthcare product with paying clients.
What is your SOC 2 status?
A formal SOC 2 program is underway, building on controls already in place. We can share current status and timeline under NDA during a security review.
How do you handle data residency and disposal?
Documented data-handling SOPs cover classification, storage, transit, and disposal. We tailor residency and retention to your requirements at scoping.
Talk to our CTO

Start with a thirty-minute conversation.

No 50-page proposals. We'll tell you which level fits your situation, what a realistic engagement looks like, and what it would cost — in one direct meeting.

Who you'll talk to
Thomas, CTO at 10decoders

Thomas

Chief Technology Officer

Connect on LinkedIn

Thomas leads 10decoders' AI engineering practice and sits in on the scoping call himself — so the person mapping your engagement is the one who has shipped it before. His teams build and deploy agents for mid-market healthcare and fintech companies, with enterprise grade build experience for clients like IBM, Dedalus and Harris Healthcare. He'll be straight with you about what's worth doing and what isn't.

200+
Engineers
37+
Global Clients
ISO
27001 / 9001

Send us an inquiry

Three fields. We'll reply within one business day.