Our role
For data you send through this website, Oracis AI LLC is the controller. When a client engagement involves personal data the client provides, we act as a processor (or "service provider") on the client's behalf, under a written agreement.
Data Processing Agreements
We'll sign a Data Processing Agreement for any engagement that involves processing personal data on your behalf, on your paper or ours. We review each one before signing, because our commitments, subprocessors, and security measures have to match what we actually do. We can't currently offer on-site audit rights. If your DPA requires them, we'll say so early.
Subprocessors for this website
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Railway | Hosting for this website and its API | Form submissions in transit; server request logs | United States |
| Supabase | Database for form submissions | Form submissions | United States (us-east-1) |
| Resend | Delivers the email notice of each form submission to our inbox | Form submissions (name, email, company, message) | United States (us-east-1) |
| GitHub | Source code hosting for this website | No visitor data | United States |
Engagements may involve additional providers, including the AI model providers used in delivery. We name them for your engagement before work starts, and tell you before adding a new one.
Healthcare data and Business Associate Agreements
Oracis is a software engineering firm. It isn't a covered entity, and it doesn't become a HIPAA business associate just by working with healthcare clients. When an engagement requires us to create, receive, maintain, or transmit protected health information on behalf of a covered entity or business associate, we'll enter into a Business Associate Agreement after reviewing that engagement's scope: the data involved, where it's hosted, and who has access. We don't sign BAAs automatically, and we don't sign one we can't operationally support.
- No protected health information may be sent to us before a BAA is signed.
- Work that uses synthetic or properly de-identified data may not need a BAA. We'll confirm that in writing for your engagement.
- Protected health information is never sent to AI models unless the specific provider and configuration are covered by the agreements in place for that engagement.
HIPAA has no certification program, and we don't claim to be "HIPAA certified" or "HIPAA compliant."