Security Architecture

Security is infrastructure,
not a checkbox.

Blackstar runs in clinical healthcare today, built on the same security model that will carry over as trades and executive logistics integrations come online. Security wasn't added on top of the system. It's the foundation the rest of it sits on.

Last reviewed July 11, 2026

Security framework

Zero-trust by default. HIPAA by design.

Every connection is isolated, credentialed, least-privilege, and logged. No shared servers, scraped logins, or third-party relay tools.

01

HIPAA Security Program

Public controls for PHI handling, access, risk, response, retention, vendors, and continuity.

Explore
02

SOC 2-aligned controls

Access, availability, monitoring, and audit controls mapped across the system stack.

03

Zero-trust network layer

Per-client credentials, isolated connections, and least-privilege access for every integration.

04

Business Associate Agreements

Executed before Blackstar handles PHI on behalf of a healthcare client.

Direct connections. No relays. No exceptions.

Every system Blackstar writes to (Open Dental, ServiceTitan, Limo Anywhere) has its own official API, and that's what we use. Each client's credentials are stored separately from every other client's. Nothing is scraped from a login screen. Nothing runs through a workaround.

Blackstar connects to your live systems through direct, credentialed APIs. Nothing sits in between. Each integration is tied to your account specifically, and covered by the same audit and access controls as everything else Blackstar runs.

Isolated. Credentialed. Auditable.

Every piece of data that moves through Blackstar is logged and kept isolated to the client it belongs to.

Call recording and transcription

Call audio is transcribed and summarized inside the client's own environment. Recordings are kept for as long as the client's retention policy specifies, and are never accessible from another account.

PHI handling

Protected health information collected during clinical intake calls is processed inside a HIPAA-compliant system. PHI is never sent to general application monitoring or third-party analytics.

Credential storage

API keys and OAuth tokens are stored in separate, isolated vaults for each client. Nothing is shared across accounts, and credentials can be rotated without taking the system down.

Audit logging

Every booking, API call, and login is logged with a timestamp and outcome. Logs are kept for compliance review, and available to clients on request.

Review our HIPAA security program.

Explore Blackstar’s public documentation covering PHI handling, access controls, incident response, breach procedures, risk management, retention, business continuity, vendor governance, workforce safeguards, and secure development.

Security questions before you sign on?

We'll walk through the full architecture, the BAA terms, and exactly how credentials are handled before any of your data moves.