Capability 03
Your AI works. Can you prove what it touches?
For CTOs, founders and security leads at health tech companies. We review what your AI actually does with patient data, map it to HIPAA technical safeguards and the SOC 2 questions buyers ask, and hand you something you can put in front of a customer or your board.
- HIPAA and SOC 2Mapped to both
- Open sourceClearMap, Apache 2.0
- Your machineCode never leaves it
What we check
Seven questions a serious buyer will ask you.
These come back in every enterprise security review and every SOC 2 readiness call. Most teams can answer two of them properly.
| Area | The question | What we usually find | What you get back |
|---|---|---|---|
| Data flow | Where does patient data actually go? | A diagram from launch week that no longer matches the code. | Traced in your code as it is today, including every third party the data reaches. |
| Prompts and context | What is being sent to the model? | Nobody has read the assembled prompt in months. | Every field that reaches a provider, and whether it needed to. |
| Retrieval | Can the AI reach data this user should not see? | Tenant boundaries assumed, never tested. | Probed directly, with the failing cases written down. |
| Output safety | What happens when it is wrong? | A disclaimer. | Where a human sits in the loop, and what the system does when they are not there. |
| Logging | Is patient data sitting in your logs? | Usually yes, and usually unnoticed. | Named, with the lines to change. |
| Evidence | Can you show a customer any of this? | A policy document written by someone who did not read the code. | A report that points at real files and real commits. |
| Controls | Does any of it map to HIPAA or SOC 2? | A spreadsheet of controls with no line of code behind them. | Each finding tied to the technical safeguard it belongs to, so the audit trail starts in the code. |
Start free
Run the scan before you talk to anyone.
ClearMap is ours, it is open source, and it runs on your machine. If it finds nothing, you have saved yourself a call.
Run it yourself
See what your own repo looks like.
ClearMap runs inside Claude Code, on your machine. Deterministic security scanning plus architectural review, mapped to HIPAA technical safeguards. Your code never leaves your laptop. Open source, Apache 2.0.
ClearMap is a technical risk signal. It is not a HIPAA certification and it is not a substitute for a full audit.
Send us the question you cannot answer yet.
The one on the security questionnaire you have been putting off, or the SOC 2 control nobody can evidence. We will tell you what it takes to answer it properly.
Thirty minutes, free, no pitch