Built for healthcare data.
Tactis handles your survey history, your policies, and your residents’ details. It’s built so that data stays isolated to your facility, every action is accounted for, and every answer can be traced back to its source.
- Plan of Correction drafted2:14p
- Sign-in · 2FA verified9:02a
Per-facility isolation
Each facility’s data is encrypted under its own key, and every database operation is scoped to that facility. One facility’s data can never surface in another’s — the facility’s identity is bound into the encryption itself. When a facility leaves, destroying its key makes its data permanently unreadable, even in retained backups.
A tamper-evident record
Every access to health information, and every disclosure to an AI subprocessor, is written to an append-only, hash-chained audit log. Altering or deleting any past entry breaks the chain and is detected — the accountability a surveyor would expect, made verifiable.
Access you control
Mandatory two-factor authentication, role-based access, and invitations your team manages. People see only what their role allows.
Documents handled carefully
Your 2567s and policies are processed in your cloud and reached through scoped, least-privilege access, never shared keys.
Encrypted in transit and at rest
The fields that carry PHI are individually encrypted at rest with per-facility keys (AES-256-GCM), and all traffic is protected with TLS. Certificates are managed and rotated automatically.
Answers you can verify
Every answer cites its source, and the engine confirms the source supports it, so the system doesn’t invent guidance.
Verifiability is a security property.
Most AI tools are a black box. You can’t see why they said what they said. Tactis answers from a specific passage and shows it, so your team can confirm every word against the regulation. Nothing is taken on faith, which is its own kind of safety.
Tactis retrieval engineYours, and used only to serve you.
- Your knowledge base holds your own regulations, policies, and forms, kept to your facility alone.
- Your account data is used to operate the service for you, not sold.
- Your data is never used to train AI models, and PHI is sent only to AI providers under agreements that prohibit training on it and, where offered, retain nothing.
- Retention and deletion are defined, so your data is kept per your agreement and returned or destroyed when the relationship ends.
- Offboarding is a true purge: destroying a facility’s encryption keys renders its data permanently unreadable, even in retained backups.
- Tactis runs on Amazon Web Services, with encryption keys managed in AWS KMS and encrypted, automated backups.
PHI is disclosed only to subprocessors covered by a Business Associate Agreement. Pinecone is used only for public regulatory content — never facility or resident data — and the application front end (Vercel) holds no PHI.
HIPAA, BAAs, and your auditors’ checklist.
When Tactis processes PHI on your behalf, we act as a business associate, and a Business Associate Agreement is available on request. We’re not SOC 2 certified today; our controls are designed and mapped to the SOC 2 2017 Trust Services Criteria, and we’re glad to walk your team or your auditors through exactly how Tactis is built and how your data is handled.
Talk to us about security.
Tell us what your organization or auditors require, and we’ll walk you through it.