RNI

Security & Compliance Disclosures

Recovery Network Inc.
Need help? info@recoverynetwork.ai

Security & Compliance Disclosures

Effective: 2026-07-31 · Rev 1
This page discloses subprocessors, data residency, and independent-assurance status as of the effective date above. It supplements, and does not replace, the executed Business Associate Agreement and Master Service Agreement between each Covered Entity and Recovery Network. See BAA §6 and MSA. Contact info@recoverynetwork.ai with questions or to request updates as our vendor footprint changes.

1. Data Residency

Recovery Network's production environment (recovery-network-v3) runs on Google Cloud Platform / Firebase, region us-central1 (Council Bluffs, Iowa), for Firestore, Cloud Functions, Cloud Storage, and associated Cloud Run services. This is the sole processing region for PHI at rest and in transit within our infrastructure; we do not multi-region replicate PHI outside us-central1 today.

2. Subprocessors

The following third parties process data on Recovery Network's behalf as of this disclosure. This list will be kept current as vendors are added, removed, or their role changes.

VendorRoleData touchedBAA status
Google Cloud / FirebaseFirestore, Cloud Functions, Cloud Storage, Speech-to-TextPHI (facility_id‑scoped)Executed BAA in place
AnthropicCouncil LLM inference (Claude models, via Cloud Function proxy — never called from the browser)De-identified clinical text; may include PHI in transit depending on facility configurationExecuted where applicable — confirm per-facility with Privacy Officer
Google (Gemini API)Council LLM inference, same proxy pattern as AnthropicSame as aboveCoverage under the Google Cloud BAA has not been separately confirmed for the Gemini API product specifically — open item, see §4
AWS (Bedrock)Council LLM inference for two of six Council models, reached via an internal Cloud Run proxy — no AWS credentials are held in this codebaseSame as aboveNot yet documented — open item, see §4
TwilioSMS delivery: crisis escalation alerts and aftercare remindersMessage content may reference facility/patient contextNot yet documented — open item, see §4
StripeBilling and subscription payment processingBilling/payment data only — no clinical or PHI dataNot applicable (no PHI touched)

HubSpot and Apollo.io appear in our marketing/sales stack as inbound-only webhook receivers (deal and outreach-event data delivered to us, HMAC-verified) — Recovery Network does not send clinical, facility, or patient data to either service, and neither is in the PHI processing path.

3. Independent Security Assessment

Recovery Network has completed an internal code-and-configuration compliance review (HIPAA Compliance Audit, 2026-07-10), covering encryption, access control, audit logging, and facility_id scoping across the platform.

A third-party penetration test against live production endpoints has not yet been performed. This is a known, budgeted item ($15,000–$40,000 estimated, Year 1) rather than an overlooked one — it is scheduled to be commissioned following initial pilot revenue. We disclose this proactively rather than waiting for it to surface in a security questionnaire, and will share the report with any Covered Entity under NDA once complete.

4. Open Items

In the interest of the same proactive disclosure, the following are not yet available. We are not representing these as complete:

Contact

Recovery Network Inc.
Attn: Privacy Officer
info@recoverynetwork.ai