Enterprise API

HIPAA compliant clinical reasoning, with zero retention of your data

The EvidenceMD API answers clinical questions with peer-reviewed citations, and it does so without keeping what you send. Zero retention of your prompts and responses. No training on your data. A signed BAA for workloads involving patient information.

HIPAA compliantZero retentionNo training on your dataEncrypted in transit and at restSOC 2 Type II in progress

Zero retention

Your prompts and our responses are not retained once the call completes. There is nothing to configure and nothing to enable — it applies to every request, on every plan.

No training on your data

Your content is never used to train, fine-tune, or evaluate any EvidenceMD model. No opt-out to find, no setting to police.

You own your data

You retain ownership of your inputs and the outputs the API returns, and you are free to use them in your product under your agreement.

Commitments

What we commit to

Six commitments, in plain terms. Each one is written into your Enterprise agreement, so it is contractual rather than aspirational.

Zero retention of your prompts and our responses
No training, fine-tuning, or evaluation on your content
You own your inputs and outputs
Encrypted in transit and at rest
A Business Associate Agreement for workloads involving patient data
Usage metadata for billing and support only — never clinical content

Status

Compliance

HIPAA

Compliant

Built for HIPAA-regulated workloads, with a Business Associate Agreement executed before any patient data flows.

SOC 2 Type II

In progress

Audit underway. Contact us for the current status and expected timeline.

Zero retention

Active

In force on every request today, by default, on every plan — not an add-on and not a setting.

Infrastructure

Security

Encryption

Traffic is encrypted in transit with TLS 1.2 or higher, and everything we store is encrypted at rest with AES-256. Plain HTTP is not accepted.

Access control

Every request is attributed to a specific API key, so usage traces to a team or environment. Keys are shown once, can be revoked instantly, and are rate limited individually.

Enterprise

What Enterprise includes

BAA for patient data

A Business Associate Agreement scoped to the clinical workflow you are actually building, signed before any PHI flows.

Raised rate limits

Standard access allows 60 requests per minute per key. Enterprise limits are set to your expected peak, agreed in writing.

Volume pricing

Committed-use pricing with invoicing, purchase orders, and annual terms in place of per-credit card payments.

Key governance

Separate keys per environment, a documented rotation procedure, and immediate revocation when a key needs to be retired.

Support and reporting

Defined availability targets, response times by severity, a named contact, and usage reporting at the interval your team needs.

Contracted terms

Data processing terms, retention commitments, and post-termination handling written into your agreement, not just documentation.

FAQ

Common questions

Do you retain the prompts and responses sent to the API?

No. We operate zero retention on your request and response content. It is not retained once the call completes. We keep only usage metadata such as which key called, the endpoint, status, latency, and credits used, which is what billing and support require.

Is the EvidenceMD API HIPAA compliant?

Yes. The API is built for HIPAA-regulated workloads, with zero retention of clinical content, encryption in transit and at rest, per-key access control, and usage records that contain no PHI. For workloads involving patient data we execute a Business Associate Agreement as part of Enterprise onboarding.

Do you sign a Business Associate Agreement?

Yes. A BAA is executed as part of Enterprise onboarding, before any patient data flows through the API. Write to krishnakumar@evidencemd.ai describing your clinical workflow and we will scope the agreement to it.

Do you train on our data?

No. Your prompts and responses are never used to train, fine-tune, or evaluate any EvidenceMD model. There is no setting to change and no opt-out to manage.

Who owns the inputs and outputs?

You do. You retain ownership of what you send and what the API returns, and you are free to use the outputs in your product under your agreement with us.

Are you SOC 2 certified?

SOC 2 Type II is in progress. Contact us for the current status and expected timeline.

Can you retrieve what the API returned last week?

No, and this is worth factoring into your own design. We can confirm that a call occurred, when it happened, how long it took, and whether it succeeded. We cannot reproduce the question or the answer, because neither was retained. If you need an audit trail of clinical content, keep it on your side.

Is no-training the same as zero retention?

They are separate commitments and you should ask any vendor about both. No-training means your content is never used to improve a model. Zero retention means your content is not kept after the request. EvidenceMD commits to both.

What are the rate limits and uptime commitments?

Standard access allows 60 requests per minute per API key, with best-effort availability and email support. Enterprise agreements carry raised limits set to your expected peak, defined availability targets, response-time commitments by severity, and a named contact.

Talk to us

Tell us the clinical workflow you are building, your expected volume, and whether patient data is involved. We will come back with the agreements your workload needs and pricing.

Krishnakumar Srinivasan

Founder & CEO

krishnakumar@evidencemd.ai
Contact us

Prefer to evaluate first? Get a self-serve API key and read the API reference.

Last updated August 8, 2026. Contractual terms for your organisation are governed by your agreement with EvidenceMD.

Enterprise Medical AI API — HIPAA Compliant, Zero Retention | EvidenceMD