Trust

Sub-processors.

The third parties we rely on to operate Aegis BioCryption, what each handles, and where. We post material changes here.

Where PHI lives. The decrypted imaging study (the pixels) never reaches any sub-processor — it is encrypted at the endpoint and stored only as ciphertext (Cloudflare R2). The audit trail and billing systems carry no patient identifiers. The limited request/study metadata required to route a study — including patient identifiers — is stored in our database (Neon), protected by encryption at rest and least-privilege access; application-level field encryption of those identifiers is on our roadmap.

Sub-processorPurposeData handledLocation
CloudflareObject storage (R2), edge, WAF, DNSEncrypted study payloads (ciphertext only)US (Eastern N. America) / APAC, per customer contract
NeonManaged PostgreSQL databaseAccount, license, and audit metadata, and request/study records (incl. patient identifiers needed to route a study)US (AWS us-east-1)
RenderApplication hosting (control plane)Runs the application; no imaging payload at restUS (Oregon)
WisePayments (USD/ACH invoicing)Billing contact email and invoice amounts; opaque organization identifier; no patient identifiersUS / EU (global payments)
ResendTransactional emailAccount and notification email addressesProvider-managed
Google AnalyticsMarketing-site analytics only (never on clinical/PHI pages)Aggregate, non-PHI web trafficProvider-managed
TelegramOperational and support notificationsSupport-ticket contents you submit; no patient identifiersProvider-managed

Last updated: June 2026. Sub-processors that handle PHI do so only as subcontractors under our HIPAA Business Associate Agreement. Need our DPA or BAA? Contact us.