Skip to main content

Know how access, data, AI, and delivery responsibility will be handled.

CAM Software works inside sensitive product, code, delivery, and business environments. Before access is granted, the engagement records what is available now, what depends on scope, and what must be completed before sensitive work can begin.

This page is a status disclosure, not a certification. A proposal identifies the controls and materials the actual scope requires; CAM Software does not claim that every procurement item is already complete.

Operating view

How the work connects across the product system.

This page is a status disclosure, not a certification. A proposal identifies the controls and materials the actual scope requires; CAM Software does not claim that every procurement item is already complete.

Current operating status

01

Available now: scoped engagement planning

Every proposal can define the product boundary, decision rights, required access, client owners, implementation guardrails, and offboarding expectations before work begins.

02

Scope-dependent: confidentiality and contracts

CAM Software can review a reasonable mutual or client NDA and document the confidentiality and data-handling obligations that apply. Acceptance depends on the actual terms and scope.

03

Scope-dependent: access and least privilege

Client-managed accounts, hardware, role-based access, separated environments, and timely offboarding can be used when the client environment and engagement support them.

04

Scope-dependent: healthcare and BAA evaluation

Prior professional experience includes healthcare, EHR, e-prescribing, and therapy products. Any BAA or HIPAA responsibility must be evaluated against the actual services, data flows, vendors, safeguards, incident duties, and insurance requirements before PHI is shared.

05

Scope-dependent: AI use and human control

AI tools, accounts, data classes, credentials, retention, permissions, and review rules must be approved for the engagement. Developers and authorized client leaders retain meaningful decisions and release authority.

06

In development: standardized procurement pack

CAM Software is formalizing a reusable policy, subprocessor, data-flow, incident, continuity, and questionnaire package. It is not represented as complete or immediately deliverable today.

Items confirmed before sensitive work begins

  • NDA and contract status
  • BAA decision when protected health information may be involved
  • Repository, environment, device, board, documentation, analytics, and release access plan
  • AI data, credential, test-data, vendor, retention, permission, and human-approval restrictions
  • Incident communication, triage, escalation, evidence, and client decision ownership
  • Specialist or subcontractor disclosure when work requires material non-mobile expertise

Not currently offered

CAM Software does not claim a security certification, blanket HIPAA compliance, independent penetration-testing capability, guaranteed incident response time, 24/7 coverage, or a complete procurement package. A qualified specialist is required when the engagement needs assurance outside CAM Software’s demonstrated scope.

Secure-development references

Where relevant, CAM Software can use the NIST Secure Software Development Framework and OWASP MASVS/MASTG to structure coverage, identify specialist needs, and make the resulting evidence and remaining risk easier to review.

Trust and procurement questions

Will CAM Software sign a BAA?

When an engagement involves protected health information, CAM Software evaluates the BAA alongside the actual services, data flows, systems, vendors, safeguards, incident duties, and insurance requirements before PHI is shared.

Can CAM Software work on a company-issued laptop?

When the scope and client environment support it, yes. Client-managed hardware, identity, and access are preferred when proprietary or regulated context should remain inside the client environment.

How does CAM Software use AI with our code or data?

AI use follows the client-approved tool, account, data, credential, retention, permission, and review policy. If those rules are not yet defined, establishing them can be part of the engagement.

Procurement should clarify risk, not hide it behind vague claims.

Share the systems, data context, access model, policies, and contract requirements that matter to your organization.

One less thing to worry about.

Discuss procurement requirements