Rōvn · Investor Room
AI agent: checking…
All sections
Compliance & Security

Vendor BAA Matrix

Current truthRōvn master canon generation 8 · effective 2026-07-21. Earlier dated diligence documents are historical snapshots, not current deployment proof.Ask the canon-grounded agent →
AI Diligence Console

Vendor BAA Matrix

Reviewed: 2026-07-22 · Canon: generation 8, effective 2026-07-21

The governing rule: every vendor that would touch real PHI has an executed BAA before real PHI exists in the system, or the data does not flow. Because the deployed environment runs synthetic data only, no vendor currently processes Rōvn-managed PHI. This matrix is therefore a gating register, and execution status for any vendor is stated only with the signed document on file.


1. Vendor gating table

Vendor classRolePHI exposure if activatedBAA gate
Google CloudCloud Run compute, Cloud SQL database, storage, Secret Manager, Vertex AIPHI at rest and in transit once real data activatesCloud BAA executed on HIPAA-covered services before any real PHI; only HIPAA-eligible services on PHI paths
AI model providersDocument extraction, drafting, workflow agents (Anthropic-first routing; runtime is model-agnostic)Credential metadata only, minimized and loggedProvider BAA plus configuration, minimization, and logging gates per 06.5 before regulated data flows
Identity verification vendorGovernment-ID identity proofing for workersIdentity documents and PIIBAA or equivalent executed before activation with real workers
Background check vendorBackground screening where a workflow requires itPII and screening data; FCRA obligations applyBAA plus FCRA workflow review by counsel before activation
Enterprise SSO (WorkOS)Customer SSO federationOrganization user identity; no clinical PHI in normal flowContract terms reviewed; BAA if scope ever includes PHI
Communications (email, SMS)Workflow notificationsContact details and notification text; designed to exclude PHIBAA required before any PHI-bearing message content
Error tracking and observabilityApplication errors and metricsNone by design; PHI scrubbing enforced before real-data activationScrubbing verified as a real-data gate; BAA if design changes
Billing processorInvoicing and paymentsBilling metadata only, never PHINo BAA required; PHI exclusion is a design rule
CloudflareDNS and selected static deliveryNone; no PHI surface is proxied through it on PHI pathsNo BAA required under current design

2. Register discipline

  • The authoritative vendor register, with counterparties, dates, and signed documents, is maintained under outside counsel (Jason Acevedo, Klehr Harrison) and shared with investors on request through diligence access.
  • Earlier dated room documents recorded vendor BAA statuses from the prior AWS-era stack. Those are historical snapshots. Under the current claim rules, execution is asserted only with the signed agreement on file, re-papered under Rōvn, Inc. where the original predates the entity conversion.
  • Renewal reviews follow the vendor register cadence; changes are logged and disclosed per the sub-processor process (06.11).

3. Customer-facing BAA

ItemStatus
TemplateMaintained under outside counsel; summary at 08.9; available on request through diligence access
Standard termsHIPAA baseline plus Rōvn-specific PHI scope and sub-processor flow-down
Signature workflowManual execution at this stage
Storage of executed BAAsImmutable artifact storage with an audit-ledger reference, per the retention design

4. Flow-down

When a customer signs a BAA with Rōvn:

  1. The customer BAA sits at the top of the cascade.
  2. Sub-processor flow-down clauses disclose the vendor list and bind downstream vendors to equivalent restrictions (08.11).
  3. Customers receive advance notice of material sub-processor changes and may raise objections per the disclosure language (06.11).
  4. Every BAA execution event is designed to be logged in the audit ledger with a reference to the stored artifact.

End of vendor BAA matrix.

Ask the AI agent about this section, the raise, compliance posture, or any cross-document question. Grounded in Rōvn canon generation 8, with on-page source citations.

Investor questions run through Google Cloud Vertex AI and are constrained to the hash-pinned Rōvn generation 8 canon. No PHI belongs in this room or its prompts.