Skip to content

Compliance & HIPAA

HIPAA security controls

The safeguards the Compliance Center manages, and what each one does.

The controls you can turn on

ControlWhat it does
Automatic LogoffSigns a user out after a period of inactivity, with a warning first. Enforced both in the app and on the server.
Secure file storageFiles on a Secure field live in a private bucket and download through short-lived signed links instead of permanent public URLs.
Password policyComplexity rules (length, mixed case, number, symbol, no common passwords) plus change, expiry, and reset flows.
Two-factor authenticationA second factor for account members and for your app's end users.
IP allow / block listsRestrict which networks can reach the app.
PHI classificationMark which tables and fields contain protected health information.

Hosting and the BAA

HIPAA-eligible apps run on Tadabase AI's AWS infrastructure, which is covered by a Business Associate Agreement. The Compliance Center shows, per interface, which hosting provider it uses and whether that provider is BAA-covered — so you can confirm a PHI-bearing interface is on covered infrastructure.

Ready to build

Skip the docs.
Just describe it.

Tadabase AI builds it, hosts it and keeps it running. Real backend, real domain, real app.

Start Building