Anchor customer

We use SoFaaS™ in production before we sell it to you.

SoFaaS™ is the runtime VectorCare built for our own Epic integration. Every hospital deployment we ship — across academic medical centers and community health systems — runs on the same platform we're now opening to other healthcare vendors. If it holds up our production traffic, it'll hold up yours.

The problem we kept hitting

VectorCare ships clinical workflow software into hospitals. Every new hospital deal had the same shape: the product was approved by the clinical buyer in weeks, then spent the next 12–18 months stuck in security review, BAA negotiation, Epic vendor process, and integration engineering.

The bottleneck wasn't software. It was compliance, distribution, and ongoing maintenance — three things that no amount of better engineering on the app itself could fix.

So we built the runtime we wished existed. Then we built it again, properly, as a platform — one that another hospital could deploy onto without us re-doing the compliance work each time.

What we built

SoFaaS™ — SMART on FHIR as a Service — is a managed runtime that owns three things on a healthcare vendor's behalf: the compliant hosting environment, the Epic Showroom listing and per-hospital deployment, and the ongoing maintenance as Epic ships changes.

The vendor's app launches inside Epic on top of it. The vendor keeps their code and their IP. Hospitals keep their data. SoFaaS™ sits between, not on top.

Read what SoFaaS™ includes

How we run it today

Time to first hospital
Weeks, not quarters

From a signed BAA to a deployed app in the hospital's Epic instance — measured in weeks, not the 12–18 months a from-scratch build takes.

Hospital footprint
One runtime, many hospitals

The same SoFaaS™ runtime serves every hospital we deploy into. Multi-tenant by design — adding the next hospital is a configuration step, not another integration project.

Security review
Evidence packet ready on request

SOC 2 Type II report, BAA, sub-processor list, and the standardized hospital security questionnaire — pre-assembled. Procurement gets what it needs the same week it asks.

We don't publish hospital names or facility counts on the public site. Our customers' procurement teams ask for that detail under NDA, and we share it then.

What broke, and what we learned

The first hospital teaches you the runtime

We learned what hospital security review actually asks for, what Epic's vendor process actually requires, and what breaks the second a real clinician opens the app. We hard-coded all of it into SoFaaS™ so the next vendor doesn't have to learn it the same way.

The tenth hospital teaches you the platform

Each new hospital wants something slightly different — a different SSO, a different EHR version, a different audit log format. SoFaaS™ abstracts that as configuration, not custom code, so we can absorb it without breaking the apps already running.

Quarterly Epic changes are the steady-state cost

Epic ships breaking changes on a cadence. We update the runtime; the apps on top keep working. It's the maintenance line item that quietly kills internal builds — and the one our customers stop seeing once they move onto SoFaaS™.

What this means for you

Every lesson the first ten hospitals taught us is already inside SoFaaS™. You don't get a brand-new platform with the rough edges still attached — you get the runtime that already passed those reviews, with the BAA template hospitals have already seen and the security packet they already know how to evaluate.

Anchor proof, not theory: the platform you'd be deploying on is the same one VectorCare's own production traffic runs through.

Have a deal stuck on Epic?

Tell us about it. Half-hour call. We'll know within 15 minutes whether SoFaaS™ can unblock you.

Talk to us