Security & compliance

Compliance Central

Every agreement, certification and safeguard behind PeptideCloud, documented in one place — for practices that handle protected health information.

Record last updated August 2026

Certification 01SOC 2 Type IICertified infrastructure layer

The cloud platform PeptideCloud runs on is independently audited over time against the Trust Services Criteria for security, availability and confidentiality.

Certification 02ISO 27001:2022Certified infrastructure layer

A certified information security management system governs how the underlying platform handles risk, access, change control and incident response.

Certification 03AIUC-1Certified infrastructure layer

AI systems used in the platform are governed by an independent standard covering safe, accountable and auditable AI operation.

Certification 04GDPRData Processing Agreement available

Personal data is processed under a Data Processing Agreement with defined controller and processor roles, subprocessor obligations and data-subject rights.

These certifications are held by the certified cloud infrastructure PeptideCloud is built on, covering the hosting, storage and processing layer beneath the product. The HIPAA program below is PeptideCloud's own.

01

HIPAA program

A signed Business Associate Agreement is executed before the first patient record can be stored.

HIPAA-01

Business Associate Agreement

Every practice executes a versioned BAA before any protected health information can be stored. Signatures are click-to-sign and recorded with signer name, title, email, IP address, user agent, timestamp and a cryptographic hash of the exact document version.

HIPAA-02

Minimum necessary access

Staff see only the records their role requires. Provider assignment mode narrows visibility further so a provider sees only the patients assigned to them.

HIPAA-03

Workforce safeguards

Unique user identification, two-step verification for staff accounts, administrator-controlled role management, and immediate revocation when a team member is removed.

HIPAA-04

Breach and incident reporting

Any use or disclosure of PHI not permitted by the agreement is reported to the practice without unreasonable delay, and in no case later than thirty calendar days after discovery.

HIPAA-05

Subcontractor obligations

Any subcontractor that touches PHI on our behalf is bound in writing to restrictions at least as restrictive as those that apply to us.

HIPAA-06

Return and destruction

On termination, PHI is returned or destroyed. Where that is infeasible, the protections of the agreement continue to apply and further use is limited.

02

Technical safeguards

Controls enforced by the software itself, not by policy alone.

CTRL-ID: AC-01

Role-based access control

Permissions are resolved from roles held in a dedicated roles store — never from the client — and every role is scoped to a single organization.

CTRL-ID: AC-02

Two-step verification

Staff accounts complete an emailed verification code before the workspace unlocks. Administrators can require it for client portal accounts too.

CTRL-ID: AC-03

Automatic session termination

Sessions end after a configurable idle period and again at an absolute maximum session length, so an unattended screen cannot stay open.

CTRL-ID: CR-01

Encryption in transit and at rest

All traffic is served over TLS, and stored records, uploaded documents and backups are encrypted at rest.

CTRL-ID: AU-01

Immutable audit logging

PHI access, modification and export are written to an append-only audit trail with actor, patient, action, timestamp and context. Administrators can filter and export the trail.

CTRL-ID: AU-02

Export controls

Every export is authorized, attributed and logged, and a daily row cap limits how much data any single account can extract.

CTRL-ID: IS-01

Tenant isolation

Each practice is a separate organization. Row-level access rules enforced in the database — not just in the interface — prevent one practice from reaching another's records.

CTRL-ID: IS-02

Restricted platform access

The internal platform console is limited to authorized platform staff behind a separate login with its own verification requirements.

03

Where PHI goes

The full path of a patient record through the platform, and the control applied at each step.

  1. 01Intake
    Encrypted submission

    Client and lead information arrives over TLS through the portal, intake forms or an authorized integration, and is attributed to one organization from the first write.

  2. 02Storage
    Encrypted, isolated

    Records and uploaded documents are encrypted at rest and stored under row-level access rules scoped to the owning organization.

  3. 03Access
    Role-checked and logged

    Each read is checked against the staff member's role and patient assignment, then recorded in the audit trail.

  4. 04Export
    Authorized and capped

    Exports and PDFs require permission, are attributed to the requesting user, and count against the organization's daily row cap.

  5. 05Retention
    Returned or destroyed

    Practices can export their full data set at any time. On termination, PHI is returned or destroyed under the terms of the BAA.

04

Legal documents

Read the agreement before you sign it. This is the exact text an administrator executes inside the product.

Business Associate Agreement

Version 2026-09-09
BUSINESS ASSOCIATE AGREEMENT
Version 2026-09-09

This Business Associate Agreement ("Agreement") is entered into by and between
PeptideCloud ("Business Associate") and the covered entity identified by the
signature below ("Covered Entity"). This Agreement supplements and is made part
of the Terms of Service between the parties.

1. DEFINITIONS
Terms used but not otherwise defined in this Agreement have the meaning given to
them in the Health Insurance Portability and Accountability Act of 1996, as
amended by the HITECH Act, and the regulations promulgated thereunder at 45 CFR
Parts 160 and 164 (collectively, "HIPAA"). "PHI" means Protected Health
Information created, received, maintained, or transmitted by Business Associate
on behalf of Covered Entity.

"PeptideCloud Fulfillment" means the optional order-fulfillment path offered
through the PeptideCloud platform, under which licensed medical review, 503A
pharmacy coordination, shipment support, and related patient-care communications
are performed for clients of Covered Entity.

"Origin Wellness" means the fulfillment partner engaged by Business Associate to
perform PeptideCloud Fulfillment. Origin Wellness is an authorized subcontractor
of Business Associate for purposes of this Agreement.

"Fulfillment Partners" means Origin Wellness and any licensed prescribing
providers, 503A compounding pharmacies, laboratories, shipping vendors, or
patient-care vendors Origin Wellness uses to carry out PeptideCloud Fulfillment.

2. PERMITTED USES AND DISCLOSURES
Business Associate may use and disclose PHI only:
  (a) to perform the services described in the Terms of Service, including
      PeptideCloud Fulfillment when selected by Covered Entity;
  (b) for the proper management and administration of Business Associate;
  (c) to provide data aggregation services relating to the health care
      operations of Covered Entity;
  (d) to Origin Wellness and other Fulfillment Partners as necessary to carry
      out PeptideCloud Fulfillment, including intake review, prescribing-support
      documentation, pharmacy coordination, shipment tracking, and patient-care
      communications about an order; and
  (e) as Required by Law.
Business Associate shall not use or disclose PHI in a manner that would violate
Subpart E of 45 CFR Part 164 if done by Covered Entity, except as permitted by
this Agreement.

3. PEPTIDECLOUD FULFILLMENT AND ORIGIN WELLNESS
If Covered Entity selects PeptideCloud Fulfillment, Covered Entity authorizes
Business Associate to disclose the minimum necessary PHI to Origin Wellness and
other Fulfillment Partners so that an order can be reviewed, prescribed where
clinically appropriate, compounded, shipped, and supported.

Covered Entity understands and agrees that:
  (a) Origin Wellness performs fulfillment services under PeptideCloud
      Fulfillment and may also act as, or coordinate with, a licensed health care
      provider or pharmacy in connection with an individual order;
  (b) clients of Covered Entity may receive shipment notices and may text or call
      a care line about their order, and that care line may identify as Origin
      Wellness;
  (c) pharmacy labels, packing inserts, and carrier records may identify the
      dispensing 503A pharmacy and may reference Origin Wellness;
  (d) Covered Entity remains responsible for its own clinical relationship with
      its clients, including protocols, billing, and the PeptideCloud client
      portal; and
  (e) if Covered Entity does not select PeptideCloud Fulfillment and instead
      connects its own provider group or pharmacy, Business Associate will not
      route that Covered Entity's orders to Origin Wellness under this Section.

4. SAFEGUARDS
Business Associate shall use appropriate administrative, physical, and technical
safeguards, and comply with Subpart C of 45 CFR Part 164 with respect to
electronic PHI, to prevent use or disclosure of PHI other than as provided for by
this Agreement. These safeguards include, without limitation: encryption of PHI
at rest and in transit; unique user identification; role-based access control;
automatic session termination after a period of inactivity; multi-factor
authentication for workforce accounts; and immutable audit logging of PHI access,
modification, and export.

5. MINIMUM NECESSARY
Business Associate shall request, use, and disclose only the minimum amount of
PHI necessary to accomplish the intended purpose of the use, disclosure, or
request, including disclosures to Origin Wellness and other Fulfillment Partners.

6. SUBCONTRACTORS
Business Associate shall ensure that any subcontractor that creates, receives,
maintains, or transmits PHI on behalf of Business Associate agrees in writing to
restrictions and conditions at least as restrictive as those that apply to
Business Associate under this Agreement, in accordance with 45 CFR
164.502(e)(1)(ii) and 164.308(b)(2).

Covered Entity acknowledges that Origin Wellness is an authorized subcontractor
for PeptideCloud Fulfillment. Business Associate shall require Origin Wellness to
bind any downstream Fulfillment Partner that handles PHI to written restrictions
at least as restrictive as those in this Agreement, to the extent HIPAA requires
a business associate agreement for that relationship. Nothing in this Section
converts a licensed provider or pharmacy that is itself a Covered Entity into a
business associate solely by receiving PHI for treatment, payment, or health care
operations.

7. REPORTING
Business Associate shall report to Covered Entity any use or disclosure of PHI
not provided for by this Agreement of which it becomes aware, including any
Security Incident and any Breach of Unsecured PHI, without unreasonable delay and
in no case later than thirty (30) calendar days after discovery. The report shall
include the information required by 45 CFR 164.410 to the extent known. Business
Associate shall require Origin Wellness to report any such incident involving
PeptideCloud Fulfillment PHI to Business Associate promptly so that Business
Associate can meet this deadline.

8. ACCESS, AMENDMENT, AND ACCOUNTING
Business Associate shall:
  (a) make PHI in a Designated Record Set available to Covered Entity as
      necessary to satisfy Covered Entity's obligations under 45 CFR 164.524;
  (b) make PHI available for amendment and incorporate amendments as directed by
      Covered Entity in accordance with 45 CFR 164.526; and
  (c) maintain and make available the information required to provide an
      accounting of disclosures in accordance with 45 CFR 164.528.
Where PHI needed for the foregoing is held by Origin Wellness or another
Fulfillment Partner, Business Associate shall obtain that PHI or cause it to be
made available to Covered Entity.

9. ACCESS BY THE SECRETARY
Business Associate shall make its internal practices, books, and records relating
to the use and disclosure of PHI available to the Secretary of the U.S.
Department of Health and Human Services for purposes of determining Covered
Entity's compliance with HIPAA, and shall require Origin Wellness to do the same
with respect to PeptideCloud Fulfillment PHI.

10. OBLIGATIONS OF COVERED ENTITY
Covered Entity shall: (a) notify Business Associate of any limitation in its
notice of privacy practices, of any changes in or revocation of an individual's
permission to use or disclose PHI, and of any restriction on the use or
disclosure of PHI to which Covered Entity has agreed, to the extent such changes
affect Business Associate's use or disclosure of PHI, including disclosures to
Origin Wellness; (b) not request that Business Associate use or disclose PHI in
any manner that would not be permissible under HIPAA if done by Covered Entity;
and (c) if Covered Entity selects PeptideCloud Fulfillment, include in its notice
of privacy practices, to the extent required, that PHI may be shared with
fulfillment partners for medical review, pharmacy coordination, shipment, and
related patient support.

11. TERM AND TERMINATION
This Agreement is effective as of the date of signature below and terminates when
all PHI is returned or destroyed, or protections are extended to such PHI in
accordance with this Section. Covered Entity may terminate the Terms of Service
if Business Associate materially breaches this Agreement and fails to cure within
thirty (30) days of written notice. Upon termination, Business Associate shall
return or destroy all PHI that it maintains in any form and retain no copies,
except where return or destruction is infeasible, in which case Business
Associate shall extend the protections of this Agreement to such PHI and limit
further uses and disclosures to those purposes that make return or destruction
infeasible. Business Associate shall direct Origin Wellness to return or destroy,
or continue to protect, PeptideCloud Fulfillment PHI on the same terms.

12. NO THIRD-PARTY BENEFICIARIES
Nothing in this Agreement confers upon any person other than the parties any
rights, remedies, obligations, or liabilities. Origin Wellness is a subcontractor
of Business Associate and is not a third-party beneficiary of this Agreement.

13. INTERPRETATION
Any ambiguity in this Agreement shall be resolved in favor of a meaning that
permits compliance with HIPAA. In the event of a conflict between this Agreement
and the Terms of Service, this Agreement controls with respect to PHI.

14. ELECTRONIC SIGNATURE
By typing your full legal name and title below and submitting this form, you
represent that you are authorized to bind the Covered Entity and you agree to be
bound by this Agreement, including the PeptideCloud Fulfillment and Origin
Wellness provisions in Section 3 if Covered Entity uses or later enables
PeptideCloud Fulfillment. Your name, title, email, IP address, user agent, and
the date and time of signature are recorded, together with a cryptographic hash
of this exact document version, as evidence of execution.

15. NOTICES
All notices, requests, and other communications under this Agreement shall be sent
to Business Associate at the following address:

Exec Groupware
Owner/Operator of PeptideCloud
382 NE 191st St
PMB 616133
Miami, Florida 33179-3899
Email: compliance@peptidecloud.ai

Questions about PeptideCloud Fulfillment or Origin Wellness under this Agreement
may be sent to the same notice address.
05

Report a vulnerability

We welcome reports from security researchers and from the practices we serve. We acknowledge receipt, investigate, and keep you updated until the issue is resolved. Please do not access, modify or retain data that is not your own while testing.

Include in your report
  • A description of the issue and the potential impact
  • The exact steps, URLs or requests needed to reproduce it
  • Any accounts, roles or test data involved
  • Your name and how you would like to be credited

Send findings and questionnaires here

Compliance questions, security reviews and vendor questionnaires go to the same address.

compliance@peptidecloud.ai
06

Compliance FAQ

Do you sign a Business Associate Agreement?

Yes. A BAA is executed inside the product before the workspace unlocks, and no protected health information can be stored until an authorized administrator signs it.

Where is our data stored?

In certified cloud infrastructure covered by SOC 2 Type II and ISO 27001:2022, encrypted in transit and at rest, with each practice isolated as its own organization.

Who can see our patients' data?

Only the staff accounts your administrators create, limited by role and — when provider assignment mode is enabled — by patient assignment. Every access is logged.

Can we export everything we put in?

Yes. Administrators can export practice data and the full audit trail at any time. Exports are authorized, attributed and logged.

What happens to PHI if we cancel?

Export your data before closing the account. After termination, PHI is returned or destroyed in accordance with the BAA; where destruction is infeasible, its protections continue to apply.

Run your practice on a platform built for PHI.

Start 7-day free trial

Compliance monitored by Exec Groupware