Volume licensing, custom branding, priority support, quarterly security reviews, and a custom DPA — built for law firms with 5 to 50 paralegals processing medical records every day.
Process 50+ case files per month with consistent chronologies, ICD/CPT extractions, and demand letters across the entire paralegal team. Enterprise volume licensing pays for itself in the first quarter.
Built-in ICD-10 and CPT code extraction, page classification, and PHI redaction profiles tuned for medical records review. Custom keyword dictionaries let you build practice-area-specific triage logic.
Centralized license management across distributed teams. Quarterly audit log exports satisfy your firm's internal compliance requirements without ad-hoc requests.
Standard for solo attorneys. Pro for small firms. Enterprise for the rest.
| Feature | Standard | Pro | Enterprise |
|---|---|---|---|
| Price | Contact us | Contact us | Contact us |
| Seats included | 1 | 1 | 5–50 (contact us for add-on pricing) |
| All 33 product tabs | ✓ | ✓ | ✓ |
| Pro-only advanced tabs | ✗ | ✓ | ✓ |
| Custom branding in reports | ✗ | ✗ | ✓ |
| Custom keyword dictionaries | ✗ | ✗ | ✓ |
| Centralized license management | ✗ | ✗ | ✓ |
| Support response SLA | 10 business days | 1 business day | 4 hours (business hours) |
| Vendor questionnaire SLA | 10 business days | 10 business days | 5 business days |
| Quarterly security review call | ✗ | ✗ | ✓ 30 min |
| Annual contract review | ✗ | ✗ | ✓ 60 min |
| Custom DPA addendum | ✗ | ✗ | ✓ |
| No-PHI Acknowledgment Letter | On request | On request | Auto-delivered at onboarding |
| Audit log export | On request | On request | Quarterly automatic |
| Custom retention scheduling | ✗ | ✗ | Negotiable |
| Right-to-audit clause | ✗ | ✗ | ✓ |
| Custom branded installer | ✗ | ✗ | ✓ |
| Onboarding video call | ✗ | ✗ | ✓ 30 min |
| Dedicated Slack/email channel | ✗ | ✗ | ✓ |
RecordIQ is a desktop application — your patient data never leaves your workstation. The compliance posture below reflects how we protect the limited license and contact metadata we DO hold, not your patient records (which we never see).
Patient data on customer workstations is encrypted with AES-256-GCM, the same standard used for US government TOP SECRET classification. The master key is wrapped by Windows DPAPI and tied to the user account.
3-pass overwrite of all temporary plaintext PHI files before unlinking, aligned with NIST SP 800-88 Rev. 1 media sanitization guidelines.
HMAC-SHA256 chained audit logs on both the customer workstation and our backend. Any tampering is detected on integrity verification.
Every support ticket subject and body passes through an automatic HIPAA Safe Harbor identifier filter (covering all 18 categories) before any storage or back-office processing.
Documented disaster recovery runbooks exercised quarterly. Q1 and Q2 2026 records on file for Enterprise customer audit.
Documented incident response runbook exercised semi-annually. Q2 2026 record covers the "stolen laptop" scenario end-to-end.
Canadian customer license data stored exclusively in Microsoft Azure Canada Central. No cross-border replication.
Backend infrastructure runs on Microsoft Azure, which holds SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, FedRAMP High, and an executed HIPAA BAA at the platform level.
Get in touch and we'll respond within 5 business days with a tailored Enterprise proposal, payment instructions, and onboarding next steps. No pressure, no high-touch sales process — just a straightforward enterprise software purchase.
Contact Sales