Live service status, incident history, and maintenance windows.
Where to look
Live service status is published at /trust/system-status/, with the live feed hosted on infrastructure independent of the product — a status page that goes down with the thing it monitors is theatre, not transparency. The status page shows current health per component, open incidents with running updates, scheduled maintenance, and historical uptime. This page explains how to read it and what our status practices are.
What the status page covers
Status is reported per component rather than as a single green dot, because “operational” means different things to different users:
- Web application — the dashboard, assessments, and reporting interface.
- API — programmatic access and integrations.
- Evidence storage — upload, retrieval, and export of evidence files.
- Background processing — report generation, notifications, and scheduled jobs.
- Third-party dependencies — status of subprocessors whose outages can affect the service, so you can distinguish our incident from an upstream one.
Each component shows one of a small set of states — operational, degraded, partial outage, major outage, maintenance — with definitions published on the status page itself so the states mean something consistent.
How we report incidents
Our incident communication rules are deliberately boring, because boring is what you want at 2 a.m.:
- Confirmed customer-impacting incidents are posted promptly after triage, with an honest initial statement of scope — including “we do not yet know the cause” when that is the truth.
- Updates follow at a stated interval while the incident is open. If we say the next update is in 30 minutes, there is an update in 30 minutes even if it only says the investigation continues.
- Resolution posts state what was affected and for how long. Significant incidents get a public post-incident summary; we do not quietly edit history after the fact.
We do not play the common game of keeping the page green during real degradation to protect an uptime statistic. Published uptime is only worth something if the incident record underneath it is honest.
What we commit to
- Confirmed customer-impacting incidents are posted to the status page within 30 minutes of triage.
- While an incident is open, updates are posted at least hourly — even when the update is “still investigating”.
- Significant incidents receive a public post-incident summary, and published history is never edited retroactively.
How status relates to the availability page
The two pages answer different questions and are kept deliberately separate. The status page answers “is the service working right now, and what happened recently?” — it is operational, real-time, and written by the engineers handling the event. The availability page answers “what does SuperHIPAA commit to, and how is the service engineered to meet it?” — SLA definitions, backup and recovery objectives, and maintenance policy. If you are building a vendor file, cite both: the commitment and the track record against it. One without the other is only half an answer.
Subscribing to updates
You should not have to poll a web page during an outage. The status page supports email and RSS subscriptions, with webhook and Slack notifications available on request, and we recommend anyone operating a compliance deadline against our product subscribes to at least one. Maintenance announcements go through the same channels ahead of the published maintenance window, so planned work never arrives as a surprise.
Status and your own compliance obligations
If your organisation treats SuperHIPAA as part of its compliance tooling, our incident history is legitimately part of your vendor file. The status page history is public precisely so you can reference it in your own vendor reviews without asking our permission. For contractual questions — whether a given incident breached the SLA, what credits apply — the service agreement governs, and the availability page describes the commitments in more detail.
Documentation available on request
- SOC 2 Type II report (under NDA)
- Penetration test summary
- Business Associate Agreement
- Architecture and data flow diagram
- Completed CAIQ / SIG Lite
Questions
Security questions go to security@superhipaa.com and get a human answer within one business day. During an active incident, the status page will always be ahead of email — check there first, then write to us if your situation needs specific handling.