Solutions · By role

The audited AI platform
for IT and security teams.

You're the one who has to approve the vendor, answer the security questionnaire, and own the incident if something goes wrong. HASP is built to make that approval defensible — isolated data planes, SSO, documented subprocessors, a tamper-evident audit chain, and an incident response process you can point your CISO at.

Compliance · frameworks we ship under
Independently validated HIPAA BAA on every paid plan
Report under NDA SOC 2 Type II · attested
Certification in progress HITRUST CSF e1
EU + UK GDPR Art. 17 · 20 · 30
Active CCPA / CPRA California
Active + CPPA-ready PIPEDA Canada
Dedicated data plane Per-org cluster on Enterprise — separate database, vector index, and object storage
SAML SSO + SCIM SSO and provisioning tied to your IdP lifecycle
30-day subprocessor notice DPA commits to advance notification — no retroactive disclosure

What you get

Everything the compliance team needs. Nothing that slows you down.

Dedicated data plane per Enterprise org

Enterprise-tier organizations run on a dedicated per-org data plane with their own database cluster, vector index, and object-storage bucket — cluster-level isolation on dedicated infrastructure.

SSO and SCIM provisioning

Enterprise SSO (SAML) — connect your IdP and enforce SSO across the entire platform. Provisioning and deprovisioning via SCIM so access follows your HR lifecycle, not your help desk queue.

Tamper-evident audit chain for every action

Every action across every surface is hash-chained and Ed25519-signed with a key bound to your organization. RFC 3161 TSA timestamp anchoring means timestamps are attested by an independent third party, not just our server clock. Chain verification runs on your own machine.

Documented subprocessors and 30-day change notice

Every third-party service that processes your data is listed in the DPA subprocessor table. HASP commits to 30 days advance notice before any subprocessor change takes effect — not retroactive disclosure after the fact.

Encryption, pen testing, and incident response

Encryption at rest and in transit across all data planes. Annual third-party penetration testing. Confirmed chain-integrity incidents trigger customer notification without undue delay, aligned with regulatory timelines under the DPA. Full security posture documented at the Trust Center.

Built-in compliance

Every action logged. Every log verifiable. By anyone.

  • Dedicated per-org data plane on Enterprise — your own database cluster, vector index, and object-storage bucket.
  • Audit chain independently verifiable on your own machine — no HASP software required, no need to trust our export UI. Download a sample audit export and run verification yourself.
  • DPA available before you sign anything — download the template at /trust and review subprocessors, data residency, and retention before committing.

The HASP platform, on this surface

Product surfaces that matter most for it & security.

See it end-to-end

Workflows that map to it & security.

Try it before you commit to anything.

Talk to us — we'll stand up an evaluation on non-patient data so you can try every surface: AI chat, document analysis, the API, the internal app builder. When your organization is ready to work with real records, countersign the BAA in-app.