Skip to content
FonteumPublic-records evidence
TRUST CENTER · COMPLIANCE & CERTIFICATIONS

What we hold today — and what we don't.

Fonteum does not currently hold SOC 2 (Type 1 or Type 2), HIPAA, or ISO 27001, and displays no badge it does not hold. The hosting and data tiers run on SOC 2 Type 2 attested infrastructure (Vercel, Supabase). For procurement that requires a specific attestation, contact security@fonteum.com.

How we substitute for a certification you can't yet rely on

  1. Attested infrastructure — hosting (Vercel) and the managed database (Supabase) both carry their own SOC 2 Type 2 reports.
  2. No PHI in scope — Fonteum processes only public CMS / OIG data, so the HIPAA and PHI-handling control surface does not apply.
  3. Radical transparency — public fields expose available source metadata and limitations, and the public corrections log records known issues. This is not a substitute certification.

Certification status

SOC 2 Type 1NOT HELD

Fonteum does not currently hold a SOC 2 Type 1 attestation and displays no badge it does not hold. The hosting and data tiers run on SOC 2 Type 2 attested infrastructure (Vercel, Supabase). For procurement requiring a specific attestation, contact security@fonteum.com.

SOC 2 Type 2NOT HELD

Fonteum does not currently hold a SOC 2 Type 2 attestation. The upstream hosting and managed-database vendors carry their own SOC 2 Type 2 reports.

HITRUSTNOT HELD

Fonteum does not currently hold a HITRUST certification. r2 (Risk-based, 2-year) is reserved for organizations handling PHI at scale; Fonteum's no-PHI architecture (see HIPAA section below) keeps it out of scope.

HIPAAN/A · NO-PHI ATTESTATION

No-PHI attestation. Fonteum processes only public CMS data, OIG LEIE records, and de-identified provider organizational data. We do not process patient identifiers, claims data, or any Protected Health Information. HIPAA covered-entity / business-associate status is not applicable to our processing scope.

BAA (Business Associate Agreement)

BAA template available on request. Because Fonteum processes no PHI, BAA execution is typically not required for data ingestion under HIPAA — the regulatory trigger is the handling of protected health information, which our processing scope excludes. The template exists as a procurement formality for partners whose internal compliance review requires a signed BAA regardless of processing scope; the no-PHI processing clause is front-and-center in our standard template.

Request the template: security@fonteum.comwith the subject "BAA template request".

Vulnerability disclosure

Security researchers: please report vulnerabilities to security@fonteum.com. Our public security contact is also published at /.well-known/security.txt per RFC 9116.

  • Acknowledgment: within 2 business days of receipt.
  • Triage: initial severity assessment within 5 business days.
  • Resolution: P0 issues patched within 7 days; P1 within 30 days; lower severity per published roadmap.
  • Disclosure: coordinated disclosure preferred. Researchers credited on /trust#security-acknowledgments with permission.

Breach notification

If a confirmed unauthorized access to user data occurs, we notify affected parties within 24 hours of confirmation and post a public statement on /corrections-log. The notification names: scope of access, affected data classes, time window, and remediation steps. We have not had a breach to date; the policy exists so the threshold is documented, not tested.

What’s on file, by the numbers

Platform snapshot · 2026-08-11

13.4Mproviders & companiesProviders, organizations, owners, and facilities on file
26.2Msource-linked factsSource-linked field facts in the dated platform snapshot
90sources with dataDistinct snapshot source IDs with at least one positive record count
73fresh sourcesDistinct source IDs whose latest positive-data snapshot falls within the preceding 45 days
111sources integratedActive registry rows; integration does not establish a load
13state Medicaid jurisdictionsDistinct states represented in the state-exclusions serving table

Integrated, with-data, and fresh-observation counts are separate. No platform-wide source-completeness count is published. Completeness is source-specific and must be evaluated against the named source's expected scope. State coverage is a separate jurisdiction measure.

Source authority is record-specific

Use the issuer named on the record.

Fonteum spans federal, state, and global public publishers. A source page or returned record identifies its issuer and dataset where that metadata is available. A platform registry count does not assign every page to one authority or establish loaded, fresh, or complete coverage.

Browse source records and their stated limitations →

Reproducible by design

Inspect the evidence each published figure actually supplies.

Source and date

Research pages expose the named public file and observation date where those fields are available. Source-file SHA-256 coverage is separate; facts do not currently link deterministically to signatures.

Available derivation

Studies with a retained release and committed derivation link the SQL or method used. Other studies state the evidence and reproduction limits they actually have.

Daily observations

Dated table row-count observations can detect local drift. They do not imply that an upstream publisher released or Fonteum ingested new data that day.

Named medical review

Reviewed by Jennifer Montecillo, MD, medical reviewer. Non-practicing medical reviewer.

Read the full provenance and attestation methodology →

Request access