Transparency

Trust Center

How GRACE Technologies secures its own operations, which vendors we rely on, and the agreements that govern them. We hold ourselves to the same standard we assess.

Last reviewed: 9/3/2026 · Reviewed quarterly

OUR COMMITMENTS

These commitments apply to every client engagement and every product we build.

HIPAA Business Associate discipline

PHI is accepted only under an executed Business Associate Agreement and only through secure channels we designate; this website collects no PHI.

No AI training on client data

Client data, engagement data, and PHI are never used to train AI models, and our AI subprocessors are contractually prohibited from doing so.

Encryption everywhere

Data is encrypted in transit (TLS) and at rest across our systems.

The vendor BAA gate

Before any tool enters a HIPAA client environment, its BAA is confirmed in writing. No signed BAA, no deployment. No exceptions.

Minimum necessary access

We access only the data required to deliver the engagement, applying HIPAA’s minimum necessary standard to our own operations.

Incident readiness

A documented incident response plan, with breach notification to affected clients within HIPAA’s required timelines or faster where our agreements demand it.

CERTIFICATIONS & REGISTRATIONS

Certified Service-Disabled Veteran-Owned Small Business (SBA VetCert)

CMMC Registered Practitioner (RP) — credential held by our founder, issued by the Cyber AB

SAM.gov — Active registration

Colorado limited liability company — Colorado Springs, Colorado

OUR VENDORS & SUBPROCESSORS

Every vendor in our operating stack, what it does, what data it touches, and the agreement that governs it. Vendors that will process Protected Health Information are added here only after a Business Associate Agreement is signed.

Vendor

What it does

Data it touches

Agreement in place

Vendor security attestations

Framer

Website hosting and forms

Site visitor data, contact form submissions (no PHI)

Standard terms + GDPR DPA

SOC 2 Type II

Cloudflare

DNS, CDN, and email routing

Network traffic metadata (no PHI)

Standard terms + DPA

SOC 2 Type II, ISO 27001

Microsoft 365

Business email, documents, calendaring

Business communications and engagement documents (no PHI via email)

Microsoft Data Protection Addendum on file

SOC 2, ISO 27001

Amazon Web Services (AWS)

Cloud infrastructure for our software products

Application and product data; PHI only within HIPAA-eligible services and only under our executed BAA

HIPAA Business Associate Addendum executed (AWS Artifact)

SOC 2, ISO 27001, HITRUST, FedRAMP

NinjaOne

Endpoint management (RMM) for GRACE-managed devices

Device inventory, patch status, and system telemetry (no PHI)

Partner agreement executed

SOC 2 Type II

Bitdefender GravityZone (deployed via NinjaOne)

Endpoint protection on GRACE-managed devices

Endpoint security telemetry (no PHI)

Provided under NinjaOne partner agreement

SOC 2

GitLab

Source code hosting and CI/CD pipelines for our software products

Source code and build artifacts (no PHI and no client data in repositories, by policy)

Standard terms

SOC 2 Type II, ISO 27001

Intuit QuickBooks Online

Accounting and invoicing

Business financial records (no PHI)

Standard terms

1Password

Credential management

Business credentials (no client PHI)

Standard terms

SOC 2 Type II

Coming online as products launch

As our software products and managed security services launch, additional vendors will be added to this register, each only after its agreement is executed: AI model providers (Anthropic), managed detection and response, backup, and security awareness training.

HOW WE SECURE OUR OWN OPERATIONS

Our internal security program is aligned to the HIPAA Security Rule and the NIST Cybersecurity Framework: multi-factor authentication on every system, encryption at rest and in transit, managed endpoint protection, DNS-layer threat filtering, patch management on a documented schedule, and a tested backup and recovery process. We run the same stack we deploy for clients, so every recommendation we make is one we live with ourselves.

REQUEST OUR DOCUMENTATION

Evaluating GRACE as a vendor? We’re glad to make that easy.

Request our BAA

Review our Business Associate Agreement before engaging us.

Privacy Policy

How we collect, use, and protect information.

Security questions

Vendor security questionnaires and due diligence requests welcomed.