Requirements
- Terminate TLS. Scan only accepts
https://webhook URLs. - Verify
X-Scan-Signature(v1=HMAC-SHA256 of{timestamp}.{raw body}) and reject timestamps older than five minutes. - During signing-secret rotation Scan may send multiple
v1=signatures for 24 hours. Accept if any matches. - Do not log raw payloads, tokens, or signing secrets.
- Rotate the webhook secret from the API access tab. The previous secret is not displayed again.
- Use synthetic data only in the sandbox.
Certifications and subprocessors
Scan maintains a SOC 2 Type II report. Email [email protected] to request it. An NDA must be in place before the report is shared. Imaging studies are retrieved from Ambra, Scan’s imaging-archive subprocessor. Notification webhooks never include study bytes; DICOM downloads go through the order-documents routes.IP allowlisting
Scan does not currently publish a static egress IP list for webhooks. Authenticate with the signature, not the source address.BAAs, retention, and incident SLAs
Contractual BAA language, retention periods, and support response times are issued by Security, Legal, and Support — they are not implied by this page. Email [email protected] for the current packet. If you suspect exposure of a Scan token or webhook secret, email [email protected] with theX-Request-Id of a recent call and
revoke the credential from the API access tab.
