This page is for:
All detection, encryption, and storage runs locally. This page documents exactly how.
mrn, ssn, patient_name)Tenet is designed to be evaluated honestly. These are the current boundaries of the technical safeguard layer.
| Area | Limitation | Mitigation |
|---|---|---|
| PostToolUse interception | Detects but cannot redact tool output — PHI reaches Claude's context before Tenet can act | Restrict PHI at the data source; pair with administrative safeguards |
| Subagent outputs | Task/subagent outputs are not currently scanned | Scope agentic workflows to non-PHI data paths |
| Detection accuracy | Probabilistic — false negatives will occur for non-standard formats and domain-specific terminology | Treat as one layer in a defense-in-depth stack |
| Physical safeguards | Tenet does not manage device-level controls | Enable FileVault full-disk encryption and screen lock |
| Multi-user monitoring | Local-only architecture has no centralized audit aggregation | Tenet Enterprise for org-wide deployment |
| Requirement | Tenet Control | Section |
|---|---|---|
| Access controls | Bearer token auth on all PHI-sensitive endpoints | 08 |
| Audit controls | Append-only JSONL, configurable 6-year retention | 05 |
| Integrity controls | AES-256-GCM with per-record nonces | 04 |
| Transmission security | Pre-transmission redaction; loopback-only binding | 01, 08 |
| De-identification | Safe Harbor §164.514(b)(2)(i) transforms | 03 |
| Criteria | Tenet Control | Section |
|---|---|---|
| CC6.1 | AES-256-GCM encryption at rest; HITL authorization gates | 04, 06 |
| CC6.3 | Explicit user authorization for sensitive operations | 06 |
| CC6.5 | TTL-based token expiration; session-scoped data | 04 |
| CC6.6 | Loopback-only network binding | 08 |
| CC7.1 | Structured audit trails with session/entity/hook filters | 05 |
| CC8.1 | Append-only audit log for change management | 05 |
| P3 | No PHI transmitted externally for processing | 08 |
| P7 | TLS 1.2+ on all endpoints | 08 |
We provide completed VSAs, penetration test summaries, and BAA templates for enterprise evaluations.
Contact us →