Convox runs inside your own cloud account, so the controls you already maintain apply to the platform: your BAA, your encryption, your network policies, your logging. Compliance is inherited from infrastructure you own, not resold as a vendor tier.
PHI stays inside your account boundary. Encryption, access control, and private networking are configuration, and your BAA with your cloud provider covers the infrastructure underneath. Contact sales about end to end HIPAA setup.
Network segmentation, role based access, and audit capability on infrastructure you control, which is what assessors actually want to trace when they follow the cardholder data.
Evidence comes from your own cloud account plus the platform's consistent, repeatable deploys, which turns control documentation from archaeology into configuration review.
Convox is compliance ready, not FedRAMP authorized. Teams pursuing authorization run it inside GovCloud style boundaries and inherit from their own environment; our FedRAMP guide covers the 2026 landscape and timelines.
Guides: why auditors reject rented platforms, HIPAA on AWS, SOC 2 in 90 days, and FedRAMP authorization planning. Or talk to an engineer about your specific framework.