Trust Center

Overview

Astraea is software delivered into the client’s own environment. Clinical data stays within the client’s security boundary, under its access policies and governance. Our approach combines that deployment model with reviewable execution and controls designed for regulated biometrics.

Security, privacy and compliance

Client-controlled deployment

Astraea supports air-gapped deployments for clients that require isolation. The software runs within client-managed infrastructure; clinical data does not need to be sent to an Astraea-hosted service. Network boundaries, permitted connections, and operational access are defined with the client before deployment.

HIPAA and sensitive information

The platform is designed around HIPAA-aligned safeguards for protected health information. Keeping PHI in the client’s environment supports control over its use and disclosure. HIPAA compliance also depends on the client’s administrative, physical, and technical safeguards, policies, and applicable agreements; an air gap alone is not a compliance determination.

SOC 2 status

SOC 2 is in progress. Astraea has not completed a SOC 2 examination and does not currently represent itself as SOC 2 certified. Security review should assess the current deployment and available evidence rather than an anticipated audit outcome.

Protecting data

Data boundary and model use

Client study data remains inside the client’s environment. Astraea does not use it to train shared or third-party models. Data-residency and access requirements remain part of the client’s deployment controls.

Encryption and retention

Astraea’s published technical guidance describes encryption in transit and at rest. Deployment planning should confirm the client’s encryption, key-management, retention, backup, and recovery requirements for the actual environment.

Purpose-limited access

Agree who may access study data, what each role may do, and how access is reviewed. The client governs its infrastructure and permissions; the software must be operated within those boundaries.

Product security and integrity

Controlled records

Versioned records and time-stamped audit trails connect actions to users and preserve review history. Astraea is designed for 21 CFR Part 11-aligned workflows, with validation evaluated against the intended use and client environment.

Human review

Qualified reviewers retain responsibility for accepting clinical outputs. Automation supports generation and checking; scientific judgment and approval stay with the team accountable for the study.

Validation and change control

Evaluate the functions that matter to the study, document expected behavior, and agree how changes will be tested and approved. The deployment should fit the client’s quality system and standard operating procedures.

Access controls and oversight

Role-based access

Astraea’s technical guidance describes role-based controls and authority checks. Configure roles around actual responsibilities and the client’s identity and access policies.

Reviewable activity

Keep execution and review evidence available to authorized users. A useful audit trail shows the action, its context, and the decision that followed, so reviewers can assess the record without reconstructing it from separate files.

Evaluate your deployment

A security review should establish the data boundary, isolation requirements, access model, validation scope, and operational responsibilities for the proposed installation. Discuss those requirements with Astraea before introducing clinical data.

SOC 2 — In progress

SOC 2 · In progress

Our security program is developing alongside the platform. This illustration denotes work in progress, not a completed audit.

Further reading: Astraea technical FAQHHS HIPAA Security Rule