What we claim, and what we do not
This page states the public boundary around Three Gates' architecture, security posture, compliance work, and company stage. It is written to answer diligence questions without implying evidence we do not have.
Current as of September 11, 2026.
Our standard
Specific claims. Visible boundaries.
A design goal is not a certification. A planned audit is not an audit in progress. A guarantee about detected data is not a guarantee of perfect detection. We keep those distinctions explicit.
Sensitive-data handling
Detected sensitive values are tokenized before every model invocation, in every tier.
Detection is probabilistic. We do not claim that every sensitive identifier will be detected.
HIPAA and BAAs
Three Gates is designed to support HIPAA Security Rule obligations and is BAA-ready for healthcare customers.
We do not claim HIPAA certification or describe the platform as universally HIPAA compliant.
NIST frameworks
Three Gates is architected to the NIST SP 800-53 Rev. 5 Moderate baseline and aligned with NIST AI RMF 1.0.
We do not claim NIST certification, accreditation, or third-party attestation.
SOC 2 and HITRUST
A SOC 2 Type II audit is planned and customer-engagement-gated. HITRUST i1 is planned to follow the initial SOC 2 Type II report.
Neither certification is held, and no audit or assessment is currently described as in progress.
Security testing
Internal security review and dependency vulnerability scanning are operational.
Third-party penetration testing is planned and customer-engagement-gated. We do not claim that it has occurred.
Encryption keys
Customer-managed encryption keys for stored work product are supported, including keys in a customer-controlled Azure Key Vault.
This does not imply private connectivity, dedicated infrastructure, or customer control of every platform key.
Policy controls
PHI policy is enforced before model invocation. Requests are authorized against a declared purpose and routed by risk level.
We do not market retired policy modes, a policy playground, destination overrides, or natural-language policy management as current product surfaces.
Company stage
Three Gates is pre-GA and accepting applications for a small design partner program.
We do not claim paying customers, production healthcare deployments, or customer logos.
Read the supporting evidence
Review measured detection results and the documented FHIR prototype.