Security is infrastructure,
not a checkbox.
Blackstar runs in clinical healthcare today, built on the same security model that will carry over as trades and executive logistics integrations come online. Security wasn't added on top of the system. It's the foundation the rest of it sits on.
Last reviewed July 11, 2026
Zero-trust by default. HIPAA by design.
Every part of the Blackstar system assumes nothing is trusted by default. Every connection needs its own credentials, is limited to exactly what it's meant to do, and is logged. Data never moves through shared servers, scraped logins, or third-party relay tools.
Clinical data processed through Blackstar meets HIPAA Technical Safeguard requirements. We maintain signed Business Associate Agreements with our healthcare clients to keep their data protected and encrypted.
Access control, availability monitoring, and audit logging follow SOC 2 Type II control categories across the full system stack.
Every integration runs through its own isolated, credentialed connection. Nothing shares a login. Nothing gets broader access than the one job it's there to do.
A signed BAA is in place with every healthcare client before we handle a single patient record — not after.
Direct connections. No relays. No exceptions.
Every system Blackstar writes to — Open Dental, ServiceTitan, Limo Anywhere — has its own official API, and that's what we use. Each client's credentials are stored separately from every other client's. Nothing is scraped from a login screen. Nothing runs through a workaround.
Blackstar connects to your live systems through direct, credentialed APIs — nothing sits in between. Each integration is tied to your account specifically, and covered by the same audit and access controls as everything else Blackstar runs.
Isolated. Credentialed. Auditable.
Every piece of data that moves through Blackstar is logged and kept isolated to the client it belongs to.
Call recording and transcription
Call audio is transcribed and summarized inside the client's own environment. Recordings are kept for as long as the client's retention policy specifies, and are never accessible from another account.
PHI handling
Protected health information collected during clinical intake calls is processed inside a HIPAA-compliant system. PHI is never sent to general application monitoring or third-party analytics.
Credential storage
API keys and OAuth tokens are stored in separate, isolated vaults for each client. Nothing is shared across accounts, and credentials can be rotated without taking the system down.
Audit logging
Every booking, API call, and login is logged with a timestamp and outcome. Logs are kept for compliance review, and available to clients on request.
Security questions before you sign on?
We'll walk through the full architecture, the BAA terms, and exactly how credentials are handled — before any of your data moves.