Security

Subprocessor list

Subprocessors that compose UNMIRI's clinical infrastructure. The PHI path lives entirely inside one AWS account (BAA active 2026-05-09). Microsoft Azure OpenAI provides narrow LLM inference under the Microsoft Online Services BAA (in force since Azure tenant activation per the Microsoft Online Services Terms; acknowledged 2026-05-09; network lockdown active 2026-05-12). Vercel hosts the marketing site only and is deliberately out of BAA scope because no PHI ever reaches it by architecture.

Last updated: June 23, 2026Contact: security@unmiri.com← Back to Security

Amazon Web Services

BAA active 2026-05-09

Entire PHI path. Single AWS BAA (executed via AWS Artifact) covers Amazon RDS Postgres (structured clinical data, variants, audit logs), Amazon S3 with SSE-KMS (encrypted document storage), AWS KMS (encryption-key management), AWS Textract (PDF extraction during the Tier-3 OCR step), AWS Lambda + API Gateway + Step Functions (compute), AWS Cognito (authentication), AWS Amplify Hosting (app surface at app.unmiri.com; the app SSR layer holds no database driver and reaches RDS only through the VPC-attached api.unmiri.com), and AWS CloudWatch Logs (audit trail). All run in a single AWS production account, us-east-1 region pinned.

Data category
All PHI flows through AWS HIPAA-eligible services within the BAA account only.
Region
us-east-1 (US East, N. Virginia)
BAA status
Active. AWS Business Associate Addendum, in effect for UNMIRI as of 2026-05-09. Account-scoped to a single production AWS account.

Microsoft Corporation

BAA active 2026-05-09

Narrow LLM inference path. Microsoft Online Services HIPAA Business Associate Agreement covers Azure OpenAI Service, used for two purposes: Tier-4 vision LLM (extraction edge cases on PDF pages that fail Tier-1/2/3 deterministic parsing) and an LLM-judge step that verifies high-uncertainty findings. Final clinical surfaces are rendered from deterministic templates, not LLM prose. Azure OpenAI network access is locked to UNMIRI's AWS NAT egress IP (firewall allow-list) as of 2026-05-12. Azure OpenAI runs under Microsoft's standard content filters and default Abuse Monitoring: UNMIRI's applications for both Modified Content Filters (declined 2026-05-10) and Abuse Monitoring opt-out (declined 2026-05-20) were declined under Microsoft's 'unmanaged customer' criterion. Because Microsoft's default Abuse Monitoring may log and sample prompts for human review, no PHI identifiers are ever placed in Azure OpenAI prompts; inputs are de-identified variant context only.

Data category
De-identified variant context and extraction prompts. No PHI identifiers in prompts.
Region
Microsoft cloud regions (US)
BAA status
Active. Microsoft General HIPAA BAA (May 2025 form), in force for UNMIRI since Azure tenant activation per the Microsoft Online Services Terms; acknowledged via Microsoft Online Services on 2026-05-09. Azure OpenAI network lockdown active as of 2026-05-12.

Vercel

Out of BAA scope by design

Marketing site hosting and edge delivery for unmiri.com only. By design, the marketing site takes no file uploads, has no authenticated routes, and never connects to RDS or any data store containing PHI. Marketing forms collect business inquiries (name, email, company, role) and route via Resend; a visible "please do not include patient information" notice sits adjacent to every free-text field. Inadvertent PHI submission is handled via the documented incident-response procedure.

Data category
Public marketing site traffic and business-inquiry form fields only. Zero PHI by architecture.
Region
US (iad1, sfo1)
BAA status
Not applicable. Out of BAA scope by design. No HIPAA add-on purchased; none required under this architecture. If marketing requirements ever change to include PHI handling, the route moves to app.unmiri.com (AWS) instead of expanding Vercel's BAA scope.

Resend

Out of BAA scope by convention

Transactional email delivery (Resend standard tier) for marketing inquiry replies, app account notifications, and Cognito authentication emails (signup verification, password reset). UNMIRI's email convention: messages never contain PHI in subject, preview, or body. Opaque report identifiers and authenticated-app links replace patient names, MRNs, and dates of birth. This convention keeps Resend out of BAA scope. If a future product requirement ever needs PHI in email content, the BAA conversation happens then; current architecture intentionally avoids it.

Data category
Marketing-form contents and authentication notifications (verification codes, password-reset links, account emails). Zero PHI by convention.
Region
US
BAA status
Not applicable. Out of BAA scope by email-content convention.

Stripe

Out of BAA scope, billing data only

Planned payment processor for Engine 3 self-serve subscriptions (Individual and Team tiers). When billing goes live, Stripe will receive the customer's email address, the selected plan tier, and payment-method details the customer enters directly into Stripe's PCI-DSS environment. UNMIRI never sees or stores card numbers. No clinical data, report content, or patient identifiers ever reach Stripe, and the pathologist tool is free and never touches billing.

Data category
Business billing data only: customer email, subscription tier, and Stripe-held payment details. Zero PHI by design.
Region
US
BAA status
Not applicable. Stripe handles business billing data only (email and plan tier), no PHI, so no BAA is required. PCI-DSS scope belongs to Stripe; UNMIRI's servers never receive card data.

Neo4j Aura

Reference data only, no PHI

Managed Neo4j graph database holding the reference evidence graph that powers Engine 3 literature intelligence. Reference clinical knowledge only: CIViC variant evidence, ClinVar identifiers, ClinicalTrials.gov metadata, openFDA drug labels and FAERS signals, CPIC pharmacogenomics guidelines, PubMed and Europe PMC identifiers, OpenAlex citation and author records, and conference-abstract metadata (Crossref). Scheduled ingesters keep this reference graph current; none of them carry PHI. UNMIRI's write-time PHI guard prevents any PHI from being persisted to Aura by design.

Data category
Public reference knowledge bases only. No PHI by design.
Region
AWS us-east-1 (Aura's managed deployment)
BAA status
Not applicable. Reference data only, no PHI.

Sentry

Out of BAA scope by configuration

Application error monitoring and performance tracing for the marketing site (unmiri.com), the app surface (app.unmiri.com), and the API (api.unmiri.com). Sentry is configured so PHI never reaches it: request bodies are never captured (request-body capture disabled), stack-trace local variables are stripped, and a before-send scrubber redacts request data, query strings, cookies, authorization headers, and user identifiers (email, IP, username) before any event leaves the process. Session Replay is disabled. This configuration keeps Sentry out of BAA scope.

Data category
Error metadata, stack traces, and performance spans with request bodies and identifiers stripped before send. Zero PHI by configuration.
Region
US (Sentry US data region)
BAA status
Not applicable. Out of BAA scope by configuration. No PHI is transmitted to Sentry, so no BAA is required (free tier in use). A PHI-bearing diagnostics need would require signing Sentry's Business-tier BAA first; this entry would then be updated.

UNMIRI is pre-pilot and pre-revenue. The architecture is in place: AWS handles the entire PHI path under a single signed BAA in us-east-1; Microsoft Azure OpenAI handles narrow LLM inference under the Microsoft Online Services BAA; Vercel hosts marketing only and is out of BAA scope by design. If a future material change adds a new subprocessor or moves PHI to a new vendor, this page is updated with the signature date and customers with active Business Associate Agreements are notified.

Notification policy

As BAAs are signed and vendors move to active status, this page will be updated with the signature date. Once UNMIRI has active Business Associate Agreements with covered-entity customers, those customers will receive notification of changes that affect their PHI, with sufficient notice to object before a change takes effect.

For vendor due-diligence questions or to ask about the status of any item on this list, email security@unmiri.com.