Security Architecture and Engineering
They Will Test What You Claim,
and the Gap Is What They Find
The Challenge
Security review is a sales stage and nobody owns it
The Strongest Control Is the Weakest Implementation
Non-Production Is Where the Exposure Sits
Certification Is Mistaken for Security
Access Accumulates
Your Incident Becomes Your Customer Incident
Logs Become a Second PHI Store
Find out what is in your non-production environments.
Not what the policy says. What is actually there: production copies, debugging extracts, demo datasets and migration snapshots. It is one of the most common serious findings and one of the cheapest to correct once located.
Our Approach
Enforce structurally, then evidence it
Step 1
Step 2
Assess how each control is enforced, distinguishing structural enforcement from application logic that has to be correct every time.
Step 3
Step 4
Reduce the protected information footprint, because the cheapest data to protect is the data you did not copy.
Step 5
Build access control around what people actually do, with support access scoped, justified, time-bound and logged.
Step 6
Step 7
Step 8
Prepare the incident capability before an incident, including what customer notification obligations require from you.
Step 9
The cheapest protected data to secure is the data you never copied.
Capabilities
Architecture, engineering, evidence
Architecture
Tenant Isolation Design
Identity and Access Architecture
Data Protection Design
Protected Information Footprint Reduction
Engineering
Application Security
DevSecOps Pipeline
dependency, static, dynamic, secret and infrastructure checks on every change.
Secrets and Credential Management
Cloud and Infrastructure Security
Evidence
Audit and Access Logging
Security Monitoring
Incident Readiness
detection, containment, investigation and customer notification.
Customer Evidence Package
What CaliberFocus does, and does not do.
Where It Applies
Every product surface has a control a reviewer will ask about
| Surface | What It Exposes | What a Reviewer Is Establishing |
|---|---|---|
| Application and User Access | What a logged-in user can reach | Whether entitlement is enforced per record or assumed from a role. |
| Reporting and Analytics | Aggregated data across records | Whether reporting inherits user scope or runs with broader access. |
| APIs and Integrations | Programmatic access at machine speed | Whether credential scope is real and whether revocation works. |
| Exports and Downloads | Data leaving the platform permanently | What an export can contain, who can generate one and whether it is logged. |
| Support and Engineering Access | Staff reaching customer data to help | Whether it is scoped, justified, time-bound and reviewed, or standing. |
| Non-Production Environments | Copies of production data | Whether real patient data is there, which is the most common finding. |
| AI and Model Paths | Prompts, retrieval, context and training data | Whether tenant boundary holds through vector stores and shared context. |
| Partner and Third-Party Access | Another company reaching your platform | What they can reach and how you assessed them. |
The Question Behind Most Healthcare Security Questionnaires
The Method
Four questions, routinely answered as one
| Question | What It Determines | What Goes Wrong When It Is Merged |
|---|---|---|
| Who Is This | Identity of the person or system | Authentication is treated as authorization, and knowing who becomes permission to act. |
| What May They Do | Capability and action | A read credential performs writes because nobody separated the two. |
| Whose Data May They Reach | Tenant and customer scope | The single most consequential failure in a multi-tenant healthcare product. |
| Which Part of It | Record, population and field scope | A user with legitimate access to a customer reaches every record in it. |
Engineering Discipline
Engineering Operations
Your incident will be your customer incident first
Detection
Logging
Containment
Investigation
Customer Notification
Pipeline Security
Dependency, static, dynamic, secret and configuration scanning on every change.
A scanner produces findings. A programme produces closure.
Trust
A certification answers a different question from the one being asked
HIPAA Engineering
Access Governance
Auditability
Operational control
Produce the list of everyone who can reach customer data across tenants.
Outcomes
Deals that do not stall, controls that hold
| Category | What We Measure | Why It Matters |
|---|---|---|
| Questions Needing Investigation | Enterprise security questions requiring an engineer to investigate before you can answer | A mature product already knows where PHI is, who can reach it and how isolation is enforced. |
| Review Cycle Time | Elapsed time from assessment starting to clearance, and engineering hours consumed | A revenue measure disguised as a compliance one. |
| Remediation Demanded | Conditions and remediation required before a deal proceeds | What the gap between claimed and implemented is costing. |
| Structural Enforcement | Controls enforced in architecture versus application logic | The honest measure, and the one a reviewer is testing. |
| Protected Data Footprint | Environments and stores holding patient data, and reduction achieved | The largest available risk reduction and simplest to explain. |
| Cross-Tenant Access Breadth | People and systems able to reach data across customers, and whether logged | The answer buyers want and usually longer than documentation suggests. |
Honest expectation setting
Reduce security risk, strengthen customer trust and accelerate enterprise readiness
Start with the clinical workflow, not the ambient AI platform.
Bring us a specialty or clinical setting where clinicians are spending too much time creating notes. We will assess where ambient documentation fits, what must remain clinician controlled, how it should integrate with your EHR, and how to measure whether it is actually reducing burden.
- AI Agents and Workflow Automation
- Voice and Conversational AI
- Document AI and Intelligent Processing
- Generative AI and Enterprise Copilots
- AI Strategy and Governance
- HCC and Risk Adjustment Analytics
Security & Compliance
