Executive Summary
AI-generated analysis for Epic
Epic (epic.com) is a well-established healthcare software company founded in 1979, assessed at Tier 3 (Moderate Risk) with a 93% confidence score. The risk tier reflects transparency gaps rather than evidence of active harm or misconduct. Epic demonstrates a number of meaningful positive signals across security and operational dimensions:
Key Findings
- The domain has been registered for over 35 years and carries a fully clean threat reputation, with no malware URLs, blacklist entries, or abuse reports detected across independent scanning sources.
- Infrastructure exposure is minimal, with only ports 80 and 443 open and zero known CVEs — a well-controlled footprint significantly below the SaaS industry average of 8–12 open ports.
- SSL/TLS configuration is strong, using TLS 1.3 with AES-256-GCM ciphers and a certificate valid through August 2026.
- The company achieved an HTTP security grade of B (75/100), with 8 of 10 tests passed.
- Epic's HITRUST CSF certification is a particularly relevant positive signal for healthcare sector buyers, as HITRUST is widely regarded as the leading assurance framework for health data environments.
- No sanctions matches, regulatory enforcement actions, or adverse media were confirmed as relevant to this vendor entity. Several transparency gaps contribute to the Tier 3 determination and warrant attention prior to or following onboarding:
- No public trust center, compliance page, or security documentation hub was found at any standard path on epic.com, which is atypical for a vendor of this scale and data sensitivity.
- No subprocessor page was identified, limiting the ability to independently assess Epic's third-party supply chain under GDPR Article 28 obligations.
- No publicly accessible AI data usage policy was found; given the healthcare context and growing AI feature sets in clinical software, the absence of a published AI data handling commitment is a notable gap.
- Three security headers — Strict-Transport-Security, Content-Security-Policy, and X-Frame-Options — are absent from the primary domain HTTP response.
- SOC 2 compliance status could not be confirmed from any publicly accessible source, though this does not indicate absence of a report. Overall, Epic presents as a long-established vendor with strong infrastructure hygiene and a meaningful HITRUST certification — but with a pattern of limited public transparency documentation that buyers must address through direct engagement. The Tier 3 rating reflects these documentation gaps, not evidence of security unavailability.
Independence Statement
All evidence in this report was independently sourced from external data providers, public registries, and open-source intelligence tools without vendor participation or input.