Skip to content
FonteumPublic-records evidence
SECURITY POSTURE

Public-records-only data. The simplest threat surface in the category.

Fonteum handles only public provider records sourced from federal and state regulatory registries. No protected health information. No personally identifiable consumer data. No payment data. The data scope is the security posture.

DATA SCOPE

What's in the dataset, and what isn't

Fonteum's dataset comprises only public regulatory-registry records: provider names, business addresses, license numbers, classification codes, NPI numbers, snapshot dates, and the source URLs they came from. These are records every American can already pull from CMS, state licensing boards, or HRSA — we aggregate, normalize, and provenance them.

Not in the dataset, by design:

  • No protected health information (PHI). We do not handle patient-level data of any kind.
  • No personally identifiable consumer information (PII). We do not collect or display consumer profiles.
  • No payment card data. Fonteum does not currently take card payments.
  • No email addresses on contractor records (CSLB and several state boards omit these by statute; we mirror that omission).

A customer integrating Fonteum data into a patient-facing product still has their own PHI/PII risk surface — but the Fonteum-supplied portion of that surface is zero. A BAA is not required because the data scope does not include protected health information.

INFRASTRUCTURE

Hosting + encryption + access

  • Hosting: Vercel (web tier), Supabase Postgres (data tier). Both are SOC 2 Type 2 attested vendors. Fonteum itself does not currently hold a SOC 2 attestation.
  • Encryption in transit: TLS 1.2+ enforced on every public endpoint via Vercel.
  • Encryption at rest: Provided by Supabase Postgres (AES-256) and Vercel infrastructure storage.
  • Access controls: Production database access limited to the operator account; service-role keys stored as Vercel environment variables, not in source.
  • Audit: Supabase row-level audit logs available; Vercel deployment logs retained per Vercel's standard retention.
PROVENANCE AS A SECURITY FEATURE

Tamper-evident by construction

Supported fields can expose a source URL, source or observation date, and confidence value. Availability varies by dataset and response; missing metadata must remain a limitation.

This isn't just an editorial choice — it's a security property. A silent tampering of any field would be detectable by re-pulling from the source URL and comparing. There is no "Fonteum-proprietary" data layer that lacks a public counterpart.

See /data-provenance for the full provenance contract.

VULNERABILITY REPORTING

How to report a finding

If you find a security issue affecting Fonteum infrastructure or data, email security@fonteum.com. We acknowledge reports within 2 business days and will keep you informed through resolution.

Good-faith security research is welcome. Please do not run automated scans that meaningfully degrade service for other users; please do not access any data beyond what's necessary to demonstrate the issue.

ROADMAP — STATED HONESTLY

Where we're not yet attested

Fonteum does not currently hold formal security attestations (SOC 2 Type 1 or Type 2, HIPAA, ISO 27001). For prospects whose procurement process requires a specific attestation, contact sales@fonteum.com to discuss the current roadmap and timeline.

We do not list speculative attestation dates on this page. If a date appears here in the future, the operator has confirmed an audit is in flight with a named auditor.

What’s on file, by the numbers

Platform snapshot · 2026-08-11

13.4Mproviders & companiesProviders, organizations, owners, and facilities on file
26.2Msource-linked factsSource-linked field facts in the dated platform snapshot
90sources with dataDistinct snapshot source IDs with at least one positive record count
73fresh sourcesDistinct source IDs whose latest positive-data snapshot falls within the preceding 45 days
111sources integratedActive registry rows; integration does not establish a load
13state Medicaid jurisdictionsDistinct states represented in the state-exclusions serving table

Integrated, with-data, and fresh-observation counts are separate. No platform-wide source-completeness count is published. Completeness is source-specific and must be evaluated against the named source's expected scope. State coverage is a separate jurisdiction measure.

Source authority is record-specific

Use the issuer named on the record.

Fonteum spans federal, state, and global public publishers. A source page or returned record identifies its issuer and dataset where that metadata is available. A platform registry count does not assign every page to one authority or establish loaded, fresh, or complete coverage.

Browse source records and their stated limitations →

Reproducible by design

Inspect the evidence each published figure actually supplies.

Source and date

Research pages expose the named public file and observation date where those fields are available. Source-file SHA-256 coverage is separate; facts do not currently link deterministically to signatures.

Available derivation

Studies with a retained release and committed derivation link the SQL or method used. Other studies state the evidence and reproduction limits they actually have.

Daily observations

Dated table row-count observations can detect local drift. They do not imply that an upstream publisher released or Fonteum ingested new data that day.

Named medical review

Reviewed by Jennifer Montecillo, MD, medical reviewer. Non-practicing medical reviewer.

Read the full provenance and attestation methodology →

Request access