Enterprise-grade posture. Because your clients trust us with what matters.
ReachABLE is designed from the ground up for zero-persistence, HIPAA-grade care, and enterprise-partner-ready procurement. Here is what we have built, what we are certifying, and how to send our documents to your vendor security team.
Zero-persistence
Free tier data never leaves the browser.
Live
SOC 2 Type II
Audit begins Year 1 of DHHS grant.
Planned 2027
BAA Available
HIPAA Business Associate Agreement on request.
Live
WCAG 2.2 AA
Section 508 aligned. VPAT 2.4 on request.
Live
Zero-persistence architecture
Data we never store cannot be breached, subpoenaed, or resold. That is the single most important security decision we have made.
Every simulator runs in your browser. Eligibility check, benefits simulator, chatbot, rollover calculator, all computed client-side with JavaScript. Nothing you type reaches our servers.
Session-only voice processing. Speech-to-text runs on-device via the Web Speech API. Audio is never uploaded.
State portal handoff via URL parameters. When you press "Open state portal," the state's own site receives your data, not us. Each state ABLE program has its own state-government privacy policy from that point.
No Social Security number collection anywhere. SSN goes directly to your state's portal on their own secure page.
Regulatory posture and certifications
Aligned with U.S. and international standards required by federal, state, and enterprise partners.
HIPAA-grade posture
Not a covered entity by definition. BAA template available for Enterprise partners who require it.
CCPA / CPRA
California consumer rights honored for every user regardless of residence.
Virginia CDPA + Colorado CPA
Universal privacy rights framework meeting all US state privacy laws.
WCAG 2.2 Level AA
Section 508 aligned. Full conformance across all consumer products.
SOC 2 Type II
Audit engagement planned Year 1 of DHHS cooperative agreement. Vanta or A-LIGN as auditor.
BIPA-safe design
Voice input transcribed on-device. No biometric collection or storage.
Northwestern IRB (FWA00001549)
Federalwide Assurance oversight for all research components.
COPPA compliant
Verifiable parental consent required for direct children under 13.
Technical controls
Standard enterprise-grade infrastructure. Auditable through the SOC 2 report when complete.
Transport encryption. TLS 1.3 for all connections. HTTP requests redirect to HTTPS.
Encryption at rest. AES-256 for any data we do store (Premium account information, aggregate analytics).
Access controls. Production data access limited to a minimum authorized personnel set. Role-based permissions. Audit logs.
No third-party trackers. No Google Analytics, no Facebook Pixel, no ad networks on the free tier. Aggregate analytics only through privacy-preserving Cloudflare or equivalent.
Annual penetration testing. Begins Year 1 of DHHS grant. Reports available to Enterprise partners under NDA.
Incident response plan. 72-hour notification to affected users and enterprise partners for any material breach.
For enterprise vendor security reviews.
Financial institutions, employers, and government agencies evaluating ReachABLE for licensing can request the full documentation packet. We turn around most requests within three business days.
Business Associate Agreement (BAA) template
VPAT 2.4 accessibility conformance report
Data Processing Addendum (DPA)
Northwestern IRB approval documentation
Architecture and data-flow diagrams
Insurance certificates carried by Northwestern University