Trust Center
Overview
Astraea is software delivered into the client’s own environment. Clinical data stays within the client’s security boundary, under its access policies and governance. Our approach combines that deployment model with reviewable execution and controls designed for regulated biometrics.
Security, privacy and compliance
Client-controlled deployment
Astraea supports air-gapped deployments for clients that require isolation. The software runs within client-managed infrastructure; clinical data does not need to be sent to an Astraea-hosted service. Network boundaries, permitted connections, and operational access are defined with the client before deployment.
HIPAA and sensitive information
The platform is designed around HIPAA-aligned safeguards for protected health information. Keeping PHI in the client’s environment supports control over its use and disclosure. HIPAA compliance also depends on the client’s administrative, physical, and technical safeguards, policies, and applicable agreements; an air gap alone is not a compliance determination.
SOC 2 status
SOC 2 is in progress. Astraea has not completed a SOC 2 examination and does not currently represent itself as SOC 2 certified. Security review should assess the current deployment and available evidence rather than an anticipated audit outcome.
Protecting data
Data boundary and model use
Client study data remains inside the client’s environment. Astraea does not use it to train shared or third-party models. Data-residency and access requirements remain part of the client’s deployment controls.
Encryption and retention
Astraea’s published technical guidance describes encryption in transit and at rest. Deployment planning should confirm the client’s encryption, key-management, retention, backup, and recovery requirements for the actual environment.
Purpose-limited access
Agree who may access study data, what each role may do, and how access is reviewed. The client governs its infrastructure and permissions; the software must be operated within those boundaries.
Product security and integrity
Controlled records
Versioned records and time-stamped audit trails connect actions to users and preserve review history. Astraea is designed for 21 CFR Part 11-aligned workflows, with validation evaluated against the intended use and client environment.
Human review
Qualified reviewers retain responsibility for accepting clinical outputs. Automation supports generation and checking; scientific judgment and approval stay with the team accountable for the study.
Validation and change control
Evaluate the functions that matter to the study, document expected behavior, and agree how changes will be tested and approved. The deployment should fit the client’s quality system and standard operating procedures.
Access controls and oversight
Role-based access
Astraea’s technical guidance describes role-based controls and authority checks. Configure roles around actual responsibilities and the client’s identity and access policies.
Reviewable activity
Keep execution and review evidence available to authorized users. A useful audit trail shows the action, its context, and the decision that followed, so reviewers can assess the record without reconstructing it from separate files.
Evaluate your deployment
A security review should establish the data boundary, isolation requirements, access model, validation scope, and operational responsibilities for the proposed installation. Discuss those requirements with Astraea before introducing clinical data.

SOC 2 · In progress
Our security program is developing alongside the platform. This illustration denotes work in progress, not a completed audit.
Further reading: Astraea technical FAQHHS HIPAA Security Rule