Trust Center
Everything a procurement reviewer, compliance officer, or auditor would ask about Tessara — in one place. Updated as we change.
Trust at a glance
Continuous evidence
Audit-log hash chain. Signed verdicts. Independently re-verifiable.
FHIR alignment matrix →Independence
No platform-vendor entanglements. Patent-pending detection methodology — Tessara doesn't resell another vendor's stack.
Open methodology
Drift detection methodology published. Re-runnable by any third party against the same public FHIR endpoints.
Drift Index Q3 2026 →Sub-processor list
Tessara discloses every external service that processes customer data or supports our production stack. This list updates within 5 business days of any sub-processor change. Tessara does not warrant third-party compliance posture — each vendor's Trust portal link below points to that vendor's own authoritative disclosure.
More to be added as Tessara onboards integrations. Tessara will update this list within 5 business days of any sub-processor change. Material changes (new region, new data category) trigger advance notice to contracted customers per the DPA.
Security artifacts
-
/.well-known/security.txt— RFC 9116 vulnerability disclosure policy and security contact. - /compliance — HIPAA compliance architecture, SOC 2 posture, FHIR alignment matrix.
- /about/vendor-risk — vendor-risk and on-premises deployment details.
- /resources/procurement — procurement packet (executive summary, security questionnaire, DPA template).
- DPA template — Data Processing Agreement. BAA available on Enterprise contracts (request via security@tessara.us).
Status
Public status page is being provisioned ahead of first pilot. In the interim, report incidents to security@tessara.us — acknowledgement target is one business day.
Security inquiries
Need a specific certification, a custom DPA, or to file a coordinated disclosure? Reach the security team directly.