EDGE ENGINE Sub-2ms Deterministic V8 Execution • Zero Data Retention Explore API Specs →
Zero Data Retention Dual-Plane HIPAA Architecture TLS 1.3 Ephemeral Isolates

Enterprise Trust, Security & Compliance

Engineered for mission-critical healthcare, banking, and global supply chain operations. Pure-compute isolation guarantees that your sensitive transactional payloads are never stored, logged, or shared.

πŸ₯ Healthcare & HIPAA β€” IN PROGRESS

HIPAA Readiness Status: Not Yet Compliant

Do not submit real PHI/PII. This platform is NOT HIPAA compliant today. Built for ANSI X12 837 claims, 835 remittances, and 270/271 eligibility standards, payloads are parsed in transient V8 memory with zero disk persistence β€” but the formal HIPAA compliance program (risk assessment, BAA, audit) is still in progress. Synthetic and de-identified data only until announced here.

  • ⚠ BAA execution not yet available (roadmap)
  • βœ” Pure in-memory AST stream transformation
  • βœ” Zero payload recording in edge access logs
🌍 Privacy & GDPR

GDPR Article 28 DPA

Full European Union data sovereignty compliance under our Zero-Retention Security Architecture. Ephemeral processing means no personal data (PII) is stored or retained beyond the milliseconds required to compute your response envelope.

  • βœ” GDPR Article 28 Data Processing Agreement
  • βœ” Local Anycast PoP execution inside EU regions
  • βœ” Zero payload persistence β€” ephemeral V8 compute only
πŸ”’ Banking & Financial

Financial Data Isolation

Built for ISO 20022 SWIFT/FedNow XML and SEPA IBAN operations. Modulo arithmetic checksums run in tight integer loops with SHA-256 constant-time proxy secret verification.

  • βœ” Strict SHA-256 + XOR constant-time auth
  • βœ” 512KB payload limits preventing ReDoS
  • βœ” 100% deterministic pure mathematical outputs

Zero-Retention Security Architecture

Unlike legacy SaaS architectures that store requests in PostgreSQL or MongoDB databases before processing, our microservices run as stateless V8 isolates at the Cloudflare edge.

Security Vector Legacy Parsing SaaS / Containers Stanza Edge Micro-APIs
Data Persistence Payloads stored in relational DBs or S3 buckets Zero disk persistence. In-memory ephemeral only.
Logging & Telemetry Raw request bodies often logged to Datadog / ELK Zero body logging. Metadata & status codes only.
Subrequest Leaks Unbounded outbound calls to 3rd party APIs Zero external subrequests. 100% pure compute.
Transport Encryption Varies, often TLS 1.2 or internal plain HTTP Strict TLS 1.3 with automated certificate rotation.
Memory Isolation Shared multi-tenant containers with memory bleed risks Hard V8 isolate boundary per request invocation.
πŸ“‹ Enterprise Vendor Assessment

CISO & Infosec Security Architecture Whitepaper

Need to clear vendor security review? Download our pre-filled security questionnaire covering TLS 1.3 encryption, zero-retention V8 memory isolates, timing-safe authentication, and disaster recovery.

View Security Whitepaper → πŸ“„ Raw Markdown

Compliance & Trust FAQ

Are EDI healthcare payloads (837P, 835, 270/271) compliant with HIPAA?
Yes, on our Enterprise HIPAA Plane. Our parsing engine runs inside ephemeral V8 isolates with zero disk persistence, zero database writes, and zero payload retention in logs. Processing live Protected Health Information (PHI) requires an executed Business Associate Agreement (BAA) and provisioning of enterprise-scoped credentials (hk_live_). Self-serve public developer tiers are architecturally segmented and restricted to synthetic, staging, and de-identified data.
Do you offer a Business Associate Agreement (BAA) or GDPR DPA?
Yes. We execute standard Business Associate Agreements (BAAs) for customers on our Enterprise plan running production healthcare EDI workloads. Standard GDPR Article 28 Data Processing Agreement (DPA) terms apply across all tiers, with custom counter-signed DPAs (including Standard Contractual Clauses) available on Ultra, Mega, and Enterprise tiers. Contact enterprise sales to review our specimen BAA.
Where is the data physically processed?
Data is processed on Cloudflare’s global Anycast edge network across 330+ cities worldwide. Compute happens in the data center closest to your initiating server, minimizing WAN transit and latency.
Can third-party subrequests intercept my financial or patient data?
No. All transformation engines are pure compute functions ($f(x)=y$) with zero external subrequests. The worker isolate cannot make outbound third-party network calls during payload processing.

Need Architecture & Compliance Details?

Download our pre-filled security whitepaper, review our specimen BAA and DPA terms, and leverage zero-retention ephemeral V8 compute isolates at the global edge.

Explore Production Plans → View Security Whitepaper →