Home / Trust Built for healthcare

Grounded, governed, and never the final word.

Every fact carries its source. Every source is checked against what it's actually licensed for. PHI is handled in memory under a signed BAA, every access is audited, and every recommendation is built to end with a clinician's sign-off.

HIPAA-aligned BAA on every live account Source-governed Human in the loop
How we handle data

Four commitments, on every live account.

These aren't aspirations bolted on at the end — they're how the platform is built to work.

PHI in memory only

Protected health information is processed in memory and never written to a persistent member cache.

  • No PHI in the member cache — output is PHI-stripped
  • Member-level Clinical Context unlocks only with a signed BAA

Audited & retained

Every access to patient data is logged, so there's always an answer to "who saw what, when."

  • Per-call audit trail across endpoints
  • Defined retention, not indefinite storage

You own the agent; a human decides

ContextRx powers your agent via MCP — you build, host, and run it. We never own, operate, or run the agent, or make the clinical call.

  • Our clinicians approve the process areas; your clinician decides
  • Calculators run deterministically, not by guess
Source governance

Licensing is a feature, not fine print.

"Free to read" rarely means "free to feed an AI." Every source is tagged with what it's actually licensed for — and anything an AI can't legally use simply isn't in the platform.

Free / redistributable

Public, redistributable sources, served directly by the platform.

Served directly
Non-commercial

Usable only within non-commercial terms, and scoped accordingly.

Scope-limited
License-required

Flows through your own license as a BYO pass-through, never resold.

BYO license
AI-prohibited

Sources whose terms forbid AI use are excluded outright — never ingested.

Excluded
Compliance posture

What we claim — and what we don't.

ContextRx is HIPAA-aligned and signs a BAA on every live account. We'd rather under-claim than overstate where we are.

On certifications: we don't claim any formal third-party security certifications on this site. When an independent certification is in place, it will be named and dated here — not before. Our standing trust commitments today are HIPAA alignment and a BAA on every live account.

Build on a platform that's accountable to a human.

Want the details — the BAA, the consent model, the governance registry? Talk to our team and we'll walk you through it.