Building Secure, Governed Agents for Regulated Enterprise

HIPAA, PHI redaction, access controls, and auditability with the Mastra framework and platform.

Brandon BarrosBrandon Barros·

Sep 28, 2026

·

6 min read

When we talk to teams in healthcare, fintech, and the public sector, security questions usually come up as specific blockers to getting into production. Can we keep PHI in our own cloud? Do you sign a BAA? How do we control who sees what, and how do we show that to our auditors?

A healthcare company handling patient data asked whether they should self-host until hosted HIPAA compliance is ready. An HR platform wanted to know which enterprise controls are open-source and which are paid. A public-safety company needed agents that follow federal, state, and local data policies at the same time. This guide covers how teams like these are building governed agent systems on Mastra.

Working through GDPR or EU data residency instead? See Building GDPR-Ready Agents with Mastra.

Background

The answer depends on which part of Mastra you're using.

Mastra framework is open-source and runs in your infrastructure. You choose the cloud, the VPC, the database, and the model provider. The only thing Mastra collects by default is anonymous CLI telemetry (OS, Mastra version, Node.js version), and you can turn that off with MASTRA_TELEMETRY_DISABLED=1.

Mastra platform hosts your Server, Studio, databases, and observability for you.

Compliance: Mastra is SOC 2 Type II audited, with HIPAA compliance coming soon. Our security controls and subprocessor list are in our Trust Center.

Enterprise security reviews tend to cover 4 things:

  1. Where your agents run
  2. What data your agents see
  3. Who can do what
  4. How you prove it

Everything inside the dashed box runs where you deploy it. Data only leaves when it goes to your model provider or your trace exporter.

1. Where your agents run

For regulated data today, we recommend self-hosting. The framework runs anywhere Node.js runs, so most teams deploy it in their own VPC on Kubernetes alongside the rest of their stack.

A healthcare team we worked with needed everything hosted in their own infrastructure for HIPAA. Their agents, workflows, and Studio all run on Kubernetes in their private cloud, so PHI stays inside it. A local government agency has a similar setup in AWS GovCloud. We covered both setups in our deployment models guide.

You don't need to host your own GPUs. Mastra calls whichever model provider you choose, so you can use one you already have a BAA with, or run your own models if you prefer.

HIPAA compliance for the hosted platform is coming soon. In the meantime, we recommend self-hosting anything that touches PHI and using the platform for everything else.

2. What data your agents see

Mastra's PIIDetector processor finds and redacts personal information like SSNs, card numbers, emails, and phone numbers. You can run it on inputs before they reach the model, on outputs, or both.

const processor = new PIIDetector({
  model: "openrouter/openai/gpt-oss-safeguard-20b",
  threshold: 0.6,
  strategy: "redact",
  detectionTypes: ["email", "phone", "credit-card", "ssn"],
});

A therapy-management company building scheduling and care-management assistants wanted to see how this works. In our demo, we sent SSNs and card numbers through an agent, and the processor redacted them before they reached the model or the trace.

For traces, SensitiveDataFilter removes the fields you specify from spans before they're exported.

Threads, working memory, workflow snapshots, datasets, and experiments are all stored in the database you configure. Healthcare teams often need to keep patient records for years, and the requirements vary by state. Since you manage the database, you set the retention period.

3. Who can do what

Mastra supports the following for access control:

  • SSO: Mastra Server and Studio work with providers like Okta, WorkOS, Clerk, and Auth0.
  • RBAC: Studio roles control who can view traces, run agents, edit workflows, or delete datasets. You can map roles from your identity provider's groups and scope permissions to individual agents.
  • Tenant and policy separation: Request context passes a user's tenant, agency, or tier into each agent call, so you can restrict tools and data per request. We recommended this approach to the public-safety company for keeping federal, state, and local agency data separate.
  • Fine-grained authorization (FGA) for field- and resource-level access.

The framework, processors, and request context are open-source. Studio SSO and RBAC are part of Mastra Enterprise Edition, and FGA is a paid add-on.

4. How you prove it

For audits, Mastra gives you a few kinds of records:

  • Traces for every agent, tool call, and workflow step, stored wherever you choose
  • Evals and metrics that track quality, cost, and error rates over time
  • Version history in Editor, which shows what changed in an agent and when, including changes made by non-technical teammates

The therapy-management team also asked how Mastra compares to building agents in a third-party workflow tool. With Mastra, your agents are part of your source code, so they go through pull request review, deploy through your own pipeline, and run in your own infrastructure.

Working through a review

Requirements vary by industry and regulator. If you have a security questionnaire, vendor review, or HIPAA checklist, send it to us and we can go through it with you.

FAQ

Is Mastra HIPAA compliant?

HIPAA compliance for the hosted platform is coming soon. For now, teams handling PHI self-host the framework in their own HIPAA-compliant infrastructure.

Do you sign BAAs?

Yes, on any plan. Reach out to our team to set one up.

Do you have SOC 2?

Yes, SOC 2 Type II. Request the report from our Trust Center.

Can we run Mastra in our own VPC?

Yes. The framework and Studio can both run entirely in your infrastructure, including Kubernetes and AWS GovCloud.

Which controls are open-source and which are paid?

The framework, processors, and request context are open-source. Studio SSO and RBAC are part of Enterprise Edition, and FGA is a paid add-on.

Share on X or LinkedIn
Brandon Barros
Brandon BarrosProduct Advocate

Brandon Barros is a Product Advocate at Mastra, helping teams scope, build, and ship AI agent systems.

All articles by Brandon Barros →