Transparency
Trust Center
How GRACE Technologies secures its own operations, which vendors we rely on, and the agreements that govern them. We hold ourselves to the same standard we assess.
Last reviewed: 9/3/2026 · Reviewed quarterly
OUR COMMITMENTS
These commitments apply to every client engagement and every product we build.
HIPAA Business Associate discipline
PHI is accepted only under an executed Business Associate Agreement and only through secure channels we designate; this website collects no PHI.
No AI training on client data
Client data, engagement data, and PHI are never used to train AI models, and our AI subprocessors are contractually prohibited from doing so.
Encryption everywhere
Data is encrypted in transit (TLS) and at rest across our systems.
The vendor BAA gate
Before any tool enters a HIPAA client environment, its BAA is confirmed in writing. No signed BAA, no deployment. No exceptions.
Minimum necessary access
We access only the data required to deliver the engagement, applying HIPAA’s minimum necessary standard to our own operations.
Incident readiness
A documented incident response plan, with breach notification to affected clients within HIPAA’s required timelines or faster where our agreements demand it.
CERTIFICATIONS & REGISTRATIONS
Certified Service-Disabled Veteran-Owned Small Business (SBA VetCert)
CMMC Registered Practitioner (RP) — credential held by our founder, issued by the Cyber AB
SAM.gov — Active registration
Colorado limited liability company — Colorado Springs, Colorado
OUR VENDORS & SUBPROCESSORS
Every vendor in our operating stack, what it does, what data it touches, and the agreement that governs it. Vendors that will process Protected Health Information are added here only after a Business Associate Agreement is signed.
Vendor
What it does
Data it touches
Agreement in place
Vendor security attestations
Framer
Website hosting and forms
Site visitor data, contact form submissions (no PHI)
Standard terms + GDPR DPA
SOC 2 Type II
Cloudflare
DNS, CDN, and email routing
Network traffic metadata (no PHI)
Standard terms + DPA
SOC 2 Type II, ISO 27001
Microsoft 365
Business email, documents, calendaring
Business communications and engagement documents (no PHI via email)
Microsoft Data Protection Addendum on file
SOC 2, ISO 27001
Amazon Web Services (AWS)
Cloud infrastructure for our software products
Application and product data; PHI only within HIPAA-eligible services and only under our executed BAA
HIPAA Business Associate Addendum executed (AWS Artifact)
SOC 2, ISO 27001, HITRUST, FedRAMP
NinjaOne
Endpoint management (RMM) for GRACE-managed devices
Device inventory, patch status, and system telemetry (no PHI)
Partner agreement executed
SOC 2 Type II
Bitdefender GravityZone (deployed via NinjaOne)
Endpoint protection on GRACE-managed devices
Endpoint security telemetry (no PHI)
Provided under NinjaOne partner agreement
SOC 2
GitLab
Source code hosting and CI/CD pipelines for our software products
Source code and build artifacts (no PHI and no client data in repositories, by policy)
Standard terms
SOC 2 Type II, ISO 27001
Intuit QuickBooks Online
Accounting and invoicing
Business financial records (no PHI)
Standard terms
—
1Password
Credential management
Business credentials (no client PHI)
Standard terms
SOC 2 Type II
Coming online as products launch
As our software products and managed security services launch, additional vendors will be added to this register, each only after its agreement is executed: AI model providers (Anthropic), managed detection and response, backup, and security awareness training.
HOW WE SECURE OUR OWN OPERATIONS
Our internal security program is aligned to the HIPAA Security Rule and the NIST Cybersecurity Framework: multi-factor authentication on every system, encryption at rest and in transit, managed endpoint protection, DNS-layer threat filtering, patch management on a documented schedule, and a tested backup and recovery process. We run the same stack we deploy for clients, so every recommendation we make is one we live with ourselves.
REQUEST OUR DOCUMENTATION
Evaluating GRACE as a vendor? We’re glad to make that easy.