Conversational AI for pharma with RoseRx
Summary from the company’s website.
Publicly advertised compliance posture
As observed on September 8, 2026 on the organization’s public trust center.
-
HIPAA
Public claim of compliance with US health-data privacy and security rules. HIPAA has no certification; compliance is self-attested.
-
SOC 2
Independent CPA audit of controls for security, availability, and confidentiality.
Compliance timeline
-
September 8, 2026
Posture last observed by Trust Index
Subprocessors
Third parties Roserx discloses on its trust center. Linked entries have their own profile in the Trust Index.
64% chain trust: 7 of 11 disclosed subprocessors are themselves in the Trust Index.
- Anthropic LLM processing for user-facing responses
- OpenAI LLM processing for AI-powered user responses
- Google Cloud Platform Hosting and data storage
- Cloudflare Cloud monitoring
- PostHog Product analytics
- Clerk User authentication and identity management
- Mailgun Transactional email delivery
- Neon Managed PostgreSQL database (includes vector storage via PGVector)
- Stripe Finance and payments
- Vercel Application hosting & blob storage
- Zendesk Customer support
About this data
The Trust Index reports only what organizations publicly advertise. A missing framework here means no public claim was observed as of September 8, 2026; it never means an organization is non-compliant. HIPAA entries reflect a public claim of compliance; no HIPAA certification exists. Corrections are welcome and verified against public evidence. Read the full methodology.