Mediaura Signal · Powered by Aura™

Security & Trust

Security your CISO can verify.

Measurement platforms ask for your most sensitive data. This page is the posture that earns it, written for the people who will audit it, not the people who will market it.

If your security team has a questionnaire, send it. We answer those for a living.

The short version.

BAA, before any data moves.

A signed Business Associate Agreement is part of every healthcare engagement, executed before a single byte of your data touches our infrastructure. Not an add-on. Not a paid tier.

A dedicated HIPAA boundary.

PHI workloads run in an isolated AWS environment purpose-built for regulated data: hardened network boundaries, encryption in transit and at rest, least-privilege access throughout.

Fail-closed audit logging.

Every administrative action and every cross-tenant access writes to a dedicated security audit channel: who, what, where, when. If logging fails, access fails. The system is built so that "we don't know who touched it" is not a possible answer.

Tenant isolation by design.

Mediaura Signal is multi-tenant, and isolation is architectural, not procedural. Access to a tenant's data requires an explicit, recorded, per-tenant grant. There are no blanket administrative keys. Your data is never visible to another client, including to our own staff without a logged, scoped grant.

AI & PHI

Aura never sees PHI.

The fastest-growing security risk in healthcare marketing isn't a breach. It's an employee pasting patient data into a consumer AI chatbot. Mediaura Signal was built so that risk is structural, not behavioral:

PHI is scrubbed at your boundary.

Identifying data is stripped before any signal leaves your environment. The analytical layer operates on de-identified, aggregated data.

The AI layer is downstream of the scrub.

Aura, our integrated AI analyst, receives only de-identified aggregates and model outputs. There is no pathway by which protected health information reaches the language model.

Your data never trains the model.

Client data is confidential and is never used for LLM training. Period.

Every number Aura cites is tool-verified.

Aura cannot invent a figure. Every quantitative claim it makes came from a structured tool call against production data, and that call is logged like any other access.

Compliance

Compliance posture.

HIPAA

Signal was built for HIPAA-regulated environments from the first commit, not retrofitted from an e-commerce product. BAA by default, server-side first-party tracking on your domain, PHI scrubbing before signal egress, and EMR/CRM-aware integration designed for PHI-restricted systems.

42 CFR Part 2

For behavioral health and substance-use treatment clients, we operate under the stricter Part 2 confidentiality requirements as a hard constraint. It shapes what we collect, what we model on, and what we surface, not just how we store it.

SOC 2 Type 2

An independent SOC 2 Type 2 examination of our security controls is scheduled. We operate to SOC 2 controls today and are formalizing the examination in 2026.

The documentation packet.

Enterprise security reviews shouldn't depend on a sales call. Under NDA, we provide:

  • Security architecture overview (data flows, boundaries, encryption, access model)
  • Audit logging specification: what is logged, where, and retention
  • Subprocessor list and data-handling commitments
  • Completed security questionnaires (SIG Lite, CAIQ, or your own format)
  • Incident response and breach notification commitments
  • SOC 2 report once the examination is complete
Request the security packet →

Ask us the hard questions.

The architecture was built for the audit. Most measurement vendors treat the security review as an obstacle between them and the contract. We treat it as the first demo.

Bold patterns. Boring rigor.

Start a security review.

Send us your questionnaire or request the documentation packet. A Mediaura engineer who knows the architecture will walk your security team through it, under NDA.

What happens next:

  • BAA executed before any data moves
  • Security architecture and data-flow walkthrough
  • Completed questionnaires (SIG Lite, CAIQ, or your own format)
  • Direct line to an engineer, not a sales rep