Update, August 29, 2026: the HIPAA half of this work is complete. Cync is now HIPAA compliant, a business associate agreement comes standard with every practice, and our Trust Center is live. The SOC 2 audit continues.
Practices ask two questions before they let software anywhere near patient information. Is it secure, and can you prove it. The first we have always answered with the product itself. The second answer is an independent audit, and that work is now underway.
What we are doing
Sprinto connects to the systems we run and watches our controls continuously: who has access to what, how data is encrypted, how sessions are managed, how vendors are reviewed, how incidents would be handled. Evidence collects itself as we work, every day, rather than being assembled by hand in the weeks before an audit.
Two programs run in parallel. SOC 2 examines the security of how we build and operate Cync. HIPAA covers the administrative, physical and technical safeguards around protected health information. Sprinto maps both against the same live picture of our infrastructure.
What is already true today
The controls the auditors will examine are the ones Cync was built on from the start: data encrypted in transit and at rest, access limited by role, a second factor on every account, and an activity record of sign-ins and changes. The compliance programs do not change how Cync works. They document and verify it.
What comes next
The monitoring window runs and the independent audit follows. Sprinto provides a live trust center, and ours is now live, so anyone can verify our compliance posture themselves, at any time.
It is the same promise the product makes, applied to ourselves: nothing left unverified.