Security and Trust Center

Enterprise-Grade Security and Compliance for Critical Oncology Data

The Pillars of Trust

SOC 2 Type II Certified

NeuralFrame undergoes annual third-party audits to verify that our security controls, operating procedures, and technical protections meet the stringent Trust Services Criteria established by the AICPA. Our comprehensive SOC 2 Type II audit proves the operational effectiveness of our controls over time. This comprehensive assessment validates our adherence to industry best practices across critical criteria, including data security, system availability, and confidentiality. Rather than treating compliance as a point-in-time event, our organization operates under a state of continuous compliance, actively monitoring our systems against these strict benchmarks. This ongoing verification gives enterprise security teams the peace of mind that their clinical registries are hosted on a platform that is dynamically protected. By executing these rigorous third-party evaluations regularly, we maintain a robust security posture that proactively adapts to emerging digital threats.

Request your copy of our SOC 2 Type II Audit Report today!

SOC 3 Public Compliance

We believe in absolute operational transparency. Our SOC 3 report is a publicly accessible document summarizing our internal controls regarding security, availability, and processing integrity. This publicly distributed report provides an executive summary of our structural and operational protections, allowing security and compliance teams to conduct rapid initial assessments without immediate legal overhead. It demonstrates our proactive stance toward corporate governance and data custodianship before a formal partnership even begins. By making these high-level findings readily available, we aim to streamline the administrative burden historically associated with vendor risk assessments in oncology care. We invite security officers and IT directors to review this transparent documentation as a testament to our structural integrity.

HIPAA Compliant

To protect Protected Health Information (PHI), NeuralFrame maintains a comprehensive HIPAA compliance program. We are verified by the Compliancy Group, demonstrating complete alignment with administrative, physical, and technical safeguards. We gladly execute Business Associate Agreements (BAAs) with all covered entities. Every member of our development, support, and implementation teams undergoes rigorous, regular training to ensure the secure handling of sensitive oncology data. Our data infrastructure utilizes isolated tenancies and advanced logical segmentation to strictly prevent unauthorized access or cross-contamination of patient records. We continuously refine our administrative policies and incident response procedures to meet or exceed federal standards for health information privacy. Our commitment to HIPAA laws and regulations ensures that critical workflows remain secure, uninterrupted, and fully compliant with all Department of Health and Human Services (HHS) regulations.

Section 508 & WCAG Accessible

Enterprise security must go hand-in-hand with inclusivity. KACI is designed to comply with Section 508 accessibility requirements and WCAG 2.2 Level AA guidelines, ensuring that Oncology Data Specialists (ODS) of all abilities can safely and seamlessly utilize our platform. We believe that an interface must be universally accessible to prevent operational fatigue and minimize user error, which are critical components of human-centric data security. Our development pipeline incorporates automated and manual accessibility testing to guarantee seamless compatibility with screen readers, keyboard-only navigation, and high-contrast displays. By empowering all oncology registrars to work in an optimized, highly accessible environment, we enhance both data accuracy and system safety. This dedication to inclusive design ensures health systems can confidently deploy KACI across diverse teams without leaving any specialist behind.

Responsible AI & Product Governance

“Registrar-in-the-Loop” — AI You Can Trust and Verify

Medical AI must never operate in a “black box.” KACI is built around the fundamental principle of human-validated AI, providing hospital compliance and oncology teams with a bulletproof audit trail.

Immutable Workflow Logging

KACI maintains a continuous, detailed record of all manual and automated actions. It tracks every change made to every cancer registry record, generating clean logs that facilitate:

  • Internal workflow validation.
  • Comprehensive performance metrics across single or multi-facility health networks.
  • Clear audit compliance for accreditation surveys (i.e. CoC, SEER, and NAACCR).

Technical Safeguards & Cloud Infrastructure

Cloud-Native Architecture Built for Modern Healthcare Systems

Secure Cloud-Native SaaS Platform

KACI is deployed on high-availability, secure cloud infrastructure. By utilizing a SaaS model, we eliminate local hardware vulnerabilities and reduce hospital IT maintenance overhead. We deploy instant security updates and standard-setter guideline revisions in the background without system downtime or manual patching.

Advanced Data Encryption

Data security is built into every layer of our tech stack:

  • In Transit: All communications between your clinical systems and KACI are secured via HTTPS utilizing industry-standard TLS 1.2 (or higher) protocols.
  • At Rest: Data stored in our secure cloud-native environments is fully encrypted using enterprise-grade AES-256 encryption.

Interoperability & Secure Ingestion

We secure clinical data pipelines at the integration point. Whether ingesting real-time pathology streams using HL7 v2 messaging (such as ORU messages) or integrating directly with FHIR-native APIs, all data transfers are fully authenticated and executed over secure, private channels.

Enterprise Identity and Access Management (IAM)

NeuralFrame natively integrates with modern enterprise Identity Providers (IdP).

  • SSO and Active Directory Integration: SSO comes standard, allowing your hospital IT team to centrally enforce user authentication.
  • Multi-Factor Authentication (MFA): We mandate MFA protocols for all platform and support access.
  • Role-Based Access Control (RBAC): Granular access controls restrict data viewing and editing rights based on defined organizational roles.