Trust & security

Legal & regulatory posture:built around zero custody.

ChicLedger's architecture reflects the experience of founders who have worked on the legal and regulatory front lines of healthcare and fintech.

What ChicLedger does not do

  • Hold claim reserves or exchange client moneyFunds move between the parties' own accounts. ChicLedger sends instructions and records the result; it never takes custody.
  • Access protected health informationThe ledger carries financial data only. We don't receive diagnoses, treatment details or medical records.
  • Adjudicate or authorize paymentClaim decisions stay with the TPA, always.
  • Receive member-level dataNo census files, names, Social Security numbers, dates of birth or eligibility rosters. Member data stays in the TPA's systems; transactions match on one-way anonymized tokens.
  • Take a fee from a standard claimStandard settlements reach the hospital at 100% of face value. A fee applies only if a hospital opts into ChicLedger Assurance.

What ChicLedger is designed to do

  • Operate as zero-custody infrastructureA record-keeping and payment-instruction layer that never takes possession of funds.
  • Role-based access, encrypted data and strict third-party vendor controlsEvery party sees only its own records. Data is encrypted in transit and at rest.
  • Align to the FTC Safeguards RuleOur information security program is designed around its requirements.
  • SOC 2 alignment in progressWe are building our controls toward a SOC 2 examination.
Principles

Proof, not promises.

Immutable record

Entries are append-only. Nothing is overwritten, so the history of every dollar stays intact and auditable.

Least-privilege access

Employers, TPAs and providers each see their own slice of the shared record, and nothing more.

Data minimization

We collect only the financial data the ledger needs, and we keep health information out of it entirely.

Standards

Designed to the frameworks your procurement team asks about.

FrameworkWhy it mattersHow ChicLedger approaches it
SOC 2 Type IIEnterprise procurementAccess controls and audit logging designed to the standard from day one; examination in preparation.
HIPAAHealth data protectionAddressed structurally: no patient-identifiable data enters the ledger, at any stage.
PCI DSSPayment instruction flowsChicLedger stores no card data.
ISO 27001 / NIST CSFInstitutional trustSecurity program aligned to both frameworks.
FTC Safeguards RuleCustomer financial informationInformation security program designed around its requirements.
Security questions

Due diligence welcome.

We're happy to walk your security, compliance and legal teams through our architecture and controls. If you believe you've found a security vulnerability, please tell us and we'll respond promptly.