Loading
Taking longer than expected.
Reload page

Security, open for review.

Give your security and procurement teams a clear view of B3IQ. Review our completed assessments, or ask for the documents your team needs to move forward.

Reviewed Sep 30, 2026

PCI external vulnerability scan

Clone Systems Inc. issued a passing scan attestation for NPC Labs, Inc., covering PCI DSS Requirement 11.3.2.

Scan completed: Sep 28, 2026. Certificate valid through: Dec 27, 2026. Scope: b3iq.org · 1 component.

This covers external vulnerability scanning for the component scanned. It is not an assessment of overall PCI DSS compliance or of our GPU fleet.

The vendor reports PASS. The executive summary also includes a scanner-configuration warning; request the report and clarification for your review.

HECVAT assessment

Completed. Our completed HECVAT questionnaire gives higher-education security teams a structured view of B3IQ's controls. Request it for your institution's vendor review.

Full questionnaire · vendor self-assessment.

Request completed HECVAT

SOC 2 Type II

In progress. Target: January 2027.

Audit underway with A-LIGN. The report has not been issued. January is a target, subject to completion of the audit.

Security practices

HIPAA readiness

In progress. Target: January 2027.

Readiness work is in progress. We already sign BAAs for agreed workloads; an executed BAA and a review of your deployment's scope are required before handling PHI.

BAA and workload scope

ISO 27001

Planned. Timing to be confirmed.

Planned for our compliance roadmap. Certification work has not started, and no certificate has been issued.

Ask about the roadmap

Documents for your review

PCI external scan certificate

Public PDF. Vendor-issued certificate · Sep 28–Dec 27, 2026 · external scan only.

Attestation of Scan Compliance

By request. Sep 28, 2026 · scan scope and vendor attestation.

PCI scan executive summary

By request. Sep 28, 2026 · findings and scanner-configuration note.

HECVAT questionnaire

By request. Full version completed · vendor security assessment.

Security policy set

By request. Access control, incident response, business continuity and data handling.

Subprocessor register

By request. Providers and the data shared with each.

Business Associate Agreement

By request. For agreed healthcare workloads · reviewed and signed by both parties.

Security and privacy

Data handling

Read our prompt retention, training and request-metadata policies. Privacy policy

Access and infrastructure

Review authentication, encryption, routing and our development practices. Security overview

Service availability

Check current availability and published incident updates. Service status

Healthcare workloads

Understand which workloads a BAA covers and your responsibilities. HIPAA and BAA scope

Common questions

What does the PCI scan establish?

This covers external vulnerability scanning for the component scanned. It is not an assessment of overall PCI DSS compliance or of our GPU fleet. PCI SSC guidance on ASV scans

Is B3IQ HIPAA certified?

HHS does not recognize private HIPAA certifications. Our readiness program and the BAA describe different things: the program is in progress, while a BAA sets out the agreed responsibilities for your specific deployment. Read the scope and setup requirements

Can I download the full reports?

The external scan certificate is public. The attestation and executive report are confidential and shared by request. Email us with the documents you need and the context of your review; please keep PHI and other sensitive workload data out of the request. Request documents by email

Where can I report a security issue?

Email contact@npclabs.org with SECURITY in the subject. Our security page describes responsible disclosure and how we handle reports. Responsible disclosure