Skip to main content

Documentation Index

Fetch the complete documentation index at: https://docs.have-foresight.app/llms.txt

Use this file to discover all available pages before exploring further.

Foresight is a HIPAA-eligible Business Associate. We sign a Business Associate Agreement (BAA) before any production access to PHI is granted.

Our controls

ControlImplementation
Encryption at restAWS KMS-managed CMKs, FIPS 140-2 validated.
Encryption in transitTLS 1.2+ on every connection.
Audit loggingEvery PHI read/write logged with actor, time, scope.
Access controlsPer-organization isolation; least-privilege scopes.
BackupRDS automated backups, point-in-time recovery 30 d.
Vulnerability managementContinuous SAST (Qodo), dependency scanning (Socket.dev, Dependabot).
Annual security assessmentSOC 2 Type II in progress; HITRUST CSF underway.
Sub-processor managementPublic list at /compliance/subprocessors.

Your responsibilities (shared model)

You’re responsible for:
  • API key safety. Treat keys as credentials.
  • Webhook signature verification. Always verify before acting.
  • Authorized users. Only assign Foresight access to workforce members with a business need.
  • Reporting. Notify us within 24 hours of any suspected breach.

BAA process

  1. Email contracts@have-foresight.com to begin.
  2. Counter-signed BAA returned within 5 business days.
  3. Production keys provisioned after the signed BAA is on file.

Reporting a security issue

Email security@have-foresight.com. We acknowledge within 24 hours and triage critical reports same-day.