← Snowpine
Security & BAA
Read this before you send us anything.
No email gate on this page. This is the current, honest state as of August 28, 2026, and it will be updated as things change. It is a plain-language summary, not the audit packet; the draft BAA, subprocessor agreements, and full security documentation arrive when you request the packet.
Where things stand today
- Snowpine runs in demo mode on fictional patients only. We do not accept protected health information yet, and the product refuses it until a business associate agreement (BAA, the HIPAA contract that makes a vendor legally liable for protecting patient data) is signed with your practice.
- The BAA is reviewed with counsel before any workspace opens. You get the agreement, this subprocessor list, and the security overview before you decide, not after.
- Snowpine is a product of Atris Labs, Inc. (Delaware). A dedicated legal entity for Snowpine is planned as the practice roster grows.
Subprocessors (who touches the infrastructure)
- Amazon Web Services — the future patient-data path: dedicated environment per practice, model calls via Bedrock under AWS's BAA. Nothing runs there yet.
- Render — application hosting for the public site and the demo API. Will not be in the patient-data path.
- Supabase — database for the site and demo (encrypted at rest). Will not hold patient data; when the BAA path opens, a patient's name lives only inside the practice's dedicated AWS environment.
- Anthropic — model provider today, demo mode only. Real patient data will route through AWS Bedrock under AWS's BAA, not the public API.
- Stripe — payments. Never sees clinical content.
Where a patient's name would live, stated plainly: today, nowhere, because demo mode accepts no patient data. When the BAA path opens, patient data lives in a dedicated AWS environment and model calls go through AWS Bedrock under AWS's BAA. Patient data will not transit Render or the public model API; those serve only this website and the demo. The BAA packet includes the data-flow diagram.
Commitments in the BAA
- Your data is never used to train any model.
- Encryption in transit and at rest, access controls, audit logs. The named controls, key management, and how you pull your own audit log are specified in the BAA packet, not summarized into adjectives here.
- Patient identifiers are kept out of server logs.
- Deletion on request, and export of everything that is yours at any time.
- Breach notification with a clock on it: suspected serious incidents reported to your practice within 24 hours of discovery, and formal breach notification within the federal 60-day maximum. California adds stricter state duties for medical information (the CMIA); meeting them is part of the counsel review that happens before any patient data enters.
What we will not do
- No patient-facing chatbot exists. The clinician is the only user.
- No diagnosis, no prescribing. Drafts are reviewed and signed by you.
- No marketing use of anything that enters a practice workspace.
Questions or the current draft BAA packet: use the request form on the front page and a person answers, not an autoresponder. Fictional demo letters, sheets, and clinical exchanges on the site are illustrations, not patient records.