SECURITY & TRUST

Built for healthcare's most sensitive decisions

Forsure protects employer, benefits, and health data with security and compliance engineered into the platform, not layered on after the fact.

TRUSTED BY HR, FINANCE & EXECUTIVE LEADERS
SOC 2
HIPAA
AI RMF
TX-RAMP
HiTrust · Coming soon
CERTIFIED & COMPLIANT

Independently certified. Continuously verified.

Forsure is held to the standards the organizations we serve require when sensitive benefits and health data are involved.

CERTIFIED

SOC 2

Audited controls covering the security, availability, and confidentiality of our systems.

COMPLIANT

HIPAA

Engineered to meet HIPAA requirements for protected health information, with BAAs available.

ALIGNED

AI RMF

Aligned to the NIST AI Risk Management Framework for trustworthy, accountable AI.

CERTIFIED

TX-RAMP

Authorized at TX-RAMP Level II for cloud services used by Texas public-sector and higher-education organizations.

IN PROGRESS

HiTrust

HiTrust certification is currently underway as we deepen our assurance program.

ENTERPRISE-GRADE PROTECTION

Security designed into every layer

From infrastructure to AI, Forsure protects your data at every step of the decision.

Security by design

Security and compliance are built into the SureSystem architecture from day one, not layered on after the fact.

Your data stays yours

Forsure does not use your data to train foundation models. Your information is used to serve you, and only you.

Encryption end to end

Data is encrypted in transit and at rest using industry-standard protocols, so sensitive information stays protected.

Controlled access

Role-based permissions, least-privilege access, and modern authentication keep data limited across multi-tennet infastructure.

Continuous monitoring

Forsure's environment is monitored on an ongoing basis, with regular audits and independent assessments.

Governed, accountable AI

Forsure's agentic AI operates within defined guardrails, with human accountability at every consequential step.

OUR APPROACH

Trust is the foundation of decision intelligence

Forsure helps HR and finance leaders make decisions on cost, risk, and care. Those decisions are only as trustworthy as the system behind them, so we treat security, privacy, and governance as core product, not paperwork.

01

Compliance built into the architecture

Rather than retrofitting controls, Forsure builds encryption, access management, audit logging, and data governance into the platform itself. Frameworks like SOC 2, HIPAA, and the AI RMF map to controls that are already in place and verifiable.

02

Responsible, governed AI

Forsure is AI-native and agentic by design. Our systems observe, decide, and act within defined guardrails, with human oversight and accountability for consequential decisions. Aligning to the NIST AI Risk Management Framework keeps that autonomy transparent and controllable.

03

Verification, on the record

Independent audits, assessments, and a continuously updated Trust Center mean our security posture is something your team can review and validate, not just take on faith.

We earn trust the way regulated industries expect it: continuously, and on the record.

TRUST CENTER

Everything your security team needs, in one place

Our Trust Center gives security, privacy, and procurement teams continuous access to Forsure's certifications, policies, sub-processors, and security documentation, ready for your next vendor review.

Go to the Trust Center
Certifications & attestations
Security & privacy policies
Sub-processor list
Architecture overview
Available under NDA for active reviews
FAQ

Security & compliance questions

The questions security, privacy, and procurement teams ask us most.

Is Forsure secure and compliant?
+

Yes. Security and compliance are built into the platform's architecture, not layered on afterward. Forsure is SOC 2 certified, HIPAA compliant, and aligned with the NIST AI Risk Management Framework (AI RMF). HiTrust certification is in progress.

Does Forsure use my data to train AI models?
+

No. Forsure does not use customer data to train foundation models. Your data is used to deliver the service to you, and it is never sold.

How is my data protected?
+

Data is encrypted in transit and at rest using industry-standard protocols. Access is governed by role-based, least-privilege controls and modern authentication, and the environment is continuously monitored.

Is Forsure HIPAA compliant? Will you sign a BAA?
+

Forsure is engineered to meet HIPAA requirements for handling protected health information. A Business Associate Agreement (BAA) is available for customers who require one.

How does Forsure govern its AI systems?
+

Forsure's agentic AI operates within defined guardrails, with human accountability for consequential decisions. Our governance program is aligned to the NIST AI Risk Management Framework.

Does Forsure undergo independent security testing?
+

Yes. Forsure's controls are validated through independent audits and assessments. Summary documentation is available through the Trust Center.

How can I review Forsure's security documentation?
+

Visit trust.forsure.ai for certifications, policies, sub-processors, and documentation. Additional materials are available under NDA to support an active security review.

What happens to my data if we stop using Forsure?
+

Customers can request an export of their data, after which it is deleted in line with our data retention policy and contractual commitments.

How does Forsure control access to my data?
+

Access is governed by role-based and attribute-based permissions with least-privilege defaults, and every request is authenticated, authorized, and logged. These controls are enforced across our multi-tenant infrastructure, where each customer's data is logically isolated so one tenant can never reach another's.

Can our security team audit Forsure or review your controls?
+

Yes. We welcome security reviews from prospective customers' teams — including security questionnaires, architecture and control walkthroughs, and reviews of our security protocols. Transparency is how we build trust, and we'll share documentation and respond to diligence requests under NDA through the Trust Center.

Bringing Forsure to your security review?

Our team will walk your security, privacy, and procurement stakeholders through Forsure's controls, certifications, and documentation, then answer questions specific to your organization. We welcome your independant security audits and security protocol review.

cross