ISO 27001:2022 certified
Our information security management system is certified to ISO/IEC 27001:2022, the international standard for managing information security risk.
Security & compliance
Arkangel AI is ISO 27001:2022 certified. HIPAA compliance and a BAA are available on Enterprise plans, backed by 70+ security controls, penetration testing and continuous monitoring via Vanta.
Arkangel AI is ISO 27001:2022 certified and offers HIPAA compliance and a BAA on Enterprise plans. More than 70 security controls cover infrastructure, data privacy and audit procedures; the platform is penetration tested and monitored continuously via Vanta. Self-serve plans are not covered by HIPAA, so do not enter patient identifiers there.
The same controls protect every plan. Certification details and policies are documented in our public Trust Center.
Our information security management system is certified to ISO/IEC 27001:2022, the international standard for managing information security risk.
HIPAA compliance and a signed Business Associate Agreement (BAA) are available on Enterprise plans. Contact us about contractual terms before your organization works with protected health information (PHI).
More than 70 controls cover infrastructure, data privacy and audit procedures.
The platform is penetration tested to identify and remediate vulnerabilities.
Controls are monitored continuously through Vanta and documented in the Arkangel AI Trust Center.
Role-based access control, secure development policies, change-management procedures, audit trails and asset-handling controls let teams collaborate across departments with traceability.
A plain-language summary of our Privacy Policy as it applies to clinical work. The Privacy Policy is the governing document.
Before you type a patient question
Unless your organization has an Enterprise agreement that covers HIPAA, remove names, record numbers, dates and any other identifiers before you ask Arkangel AI a question.
Privacy questions: dpo@arkangel.ai
Arkangel AI supports healthcare professionals. It does not provide medical advice, diagnosis or treatment on its own, and our approach follows international guidance on AI for health.
Clinicians and reviewers validate every finding. The final clinical, coding or audit decision stays with your team.
Answers link to the studies, guidelines and records they rely on, so professionals can check the evidence themselves.
We state what the product does not do and ask users to verify the original sources before acting on an answer.
Use de-identified inputs on self-serve plans, and an Enterprise agreement with HIPAA compliance when PHI is involved.
Six principles for AI in health, including human oversight, transparency and accountability.
Recommendations for generative AI used in health care.
Describes software that supports clinicians' judgment and lets them independently review the basis for its recommendations.
Yes, on Enterprise plans: Arkangel AI offers HIPAA compliance and signs a Business Associate Agreement (BAA); contact us about contractual terms. Inputs on the self-serve Free, Pro and Team plans are not covered by HIPAA, so do not enter protected health information there. Arkangel AI is also ISO 27001:2022 certified, with 70+ security controls monitored via Vanta.
Consumer ChatGPT is not HIPAA compliant by default, so clinicians should not paste patient identifiers into it. Some enterprise AI offerings support HIPAA through a Business Associate Agreement (BAA). Before any tool handles PHI, confirm its current contract terms, encryption, role-based access and audit trails, and keep identifiers out of consumer chatbots.
AI can safely support diagnosis when it is validated, protects patient data and a clinician reviews every output; it should not diagnose on its own. WHO and FDA guidance both stress human oversight and transparency. In Arkangel AI, each answer links to its sources and the final clinical decision stays with the healthcare team.
WHO guidance on the ethics and governance of AI for health sets six principles: protect autonomy; promote well-being, safety and the public interest; ensure transparency and explainability; foster responsibility and accountability; ensure inclusiveness and equity; and promote responsive, sustainable AI. It calls for human oversight and evaluation in real-world settings.
Yes. Arkangel AI is ISO 27001:2022 certified. Its security program includes more than 70 controls covering infrastructure, data privacy and audit procedures, plus penetration testing and continuous monitoring via Vanta. Certification details and policies are available in the Arkangel AI Trust Center at compliance.arkangel.ai.
Talk to our team about HIPAA scope, the Enterprise BAA, contractual terms and your security review. Our Trust Center has the documentation your security team will ask for.
Last updated: