πSECURITY & TRUST REPORT
Enterprise-Grade Financial Intelligence
for Modern Healthcare
At Shteg.ai, we understand that in healthcare, Data is Trust. Our platform is built on a Security-First architecture designed to handle nationwide credentialing and revenue cycle management.
π‘οΈ
SOC 2 Type II
Annual Independent Audit
βοΈ
HIPAA / HITECH
BAA Executed with All Partners
π
CMS Schema 2.0
2026 Interoperability Ready
π
FIDO2 / WebAuthn
Phishing-Resistant MFA
ποΈ
1. Compliance & Certification
SOC 2 Type II Certified:Annual independent audits verify all five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
HIPAA & HITECH Compliant:All workflows exceed HIPAA standards. Formal Business Associate Agreements (BAAs) are executed with every partner and sub-processor.
CMS Schema 2.0 Ready:Data ingestion engines are fully compliant with the 2026 federal Interoperability and Patient Access mandates β including actual allowed amounts and percentile data.
π
2. Data Protection & Encryption
End-to-End Encryption:Data encrypted at rest with AES-256 and in transit via TLS 1.3. Financial and clinical data never travels over unencrypted channels.
Zero-Knowledge Architecture:Federal system credentials (NPDB / FSMB) are stored in hardware-security modules (HSMs). They are never accessible to Shteg.ai staff.
Phishing-Resistant MFA:All administrative and developer access requires FIDO2 / WebAuthn hardware keys, eliminating credential-theft risk entirely.
π
3. National Integration Security
Federal Gateway Security:Connections to the NPDB (QRXS) and FSMB use certificate-based authentication β the same standard used by federal health agencies.
TEFCA / QHIN Framework:Clinical data exchange is governed by the Trusted Exchange Framework and Common Agreement, ensuring legal and technical interoperability nationwide.
Immutable Audit Logging:Every data access event is logged in a time-stamped, append-only audit trail. Full transparency for internal or external compliance reviews. Retained 6 years per HIPAA mandate.
β‘
4. Reliability & The Antigravity Advantage
Multi-Region Failover:Built on Google Cloud. If a primary data center goes offline, Shteg.ai automatically fails over, ensuring 99.9% availability SLA.
Real-Time Threat Detection:AI-driven monitoring identifies and neutralizes anomalous behavior β such as unauthorized NPI queries β in milliseconds.
API Rate Limit Resilience:Exponential backoff with Β±30% jitter prevents cascade failures when federal endpoints (CMS / NPDB) throttle during high-volume credentialing sweeps.
"Our mission is to empower providers with data. Our mandate is to protect it."
β Dalip Turkeshi, Founder, Shteg.ai
Ready to review the full diligence package?
Request our SOC 2 Type II report, BAA template, and Vendor Risk Assessment.
Contact Security Team β