Sovereign by default. Your account. Your keys.
Tarevo is built on the assumption that clinical data should never be held hostage by a vendor. Every deployment runs in infrastructure you own, with encryption keys you control, and access that is revocable on demand.
Operating posture
What sovereignty looks like in practice.
The four properties a security or procurement reviewer will ask about — and how Tarevo implements each one.
Customer-owned AWS account
Every Tarevo deployment runs in your AWS account — not ours, not a shared multi-tenant cluster. You control the account, the network boundaries, and the IAM policies.
Customer-held KMS keys
Encryption keys live in your AWS KMS. Tarevo never holds a copy and cannot decrypt your data without your active grant — which you can revoke on a single API call.
Delegated, revocable IAM
Access for the Tarevo engineering team is scoped, time-bound, and auditable. When the engagement ends, our privileges drop; your records stay where they are.
HIPAA & 42 CFR Part 2
BAA in place per deployment. Part 2-segmented records are kept separate from general PHI, with consent tracking at the encounter level.