New: CentriCall AI voice agents that answer, qualify, and book around the clock
Massachusetts, United States · Eastern Time

Software development for Boston companies, on Eastern Time

Centricone works remotely with companies across Boston and eastern Massachusetts — health and life sciences integration, platform engineering, and data work, designed against a state data-security regulation that is more prescriptive than most privacy statutes.

How this works

We work with Boston remotely, and we say so

Centricone has no office in Boston. We deliver remotely, on Eastern Time, with senior contacts available through your working day and 24/7 escalation for production systems under a support agreement.

Boston concentrates academic medical centres, life sciences, and a deep enterprise software sector, so the work here is weighted toward integration with clinical and research systems and toward platforms handling data whose provenance matters as much as its accuracy. It is a market where a security review is assumed rather than negotiated.

Eastern Time

Your working day, not an overlap window at the edges of it.

Your regime

Designed against the rules that apply where you operate.

One business day

The reply time we hold ourselves to on any enquiry.

The rules that apply to Massachusetts companies

Massachusetts has no omnibus consumer privacy act, but it has something unusual — a data security regulation that prescribes specific controls rather than describing outcomes.

  • 201 CMR 17.00, which requires a written information security program with named controls
  • Encryption of personal information in transit and on portable devices, stated explicitly
  • Third-party service provider contract requirements, which reach vendors like us
  • HIPAA where the client is a provider, payer, or business associate
  • Massachusetts breach-notification duties, which carry regulator reporting alongside consumer notice

Working with Boston

Something specific to your market? Ask us directly.

No. We work remotely with Massachusetts clients on Eastern Time, which is the same working day we keep ourselves.
It is prescriptive. Most privacy statutes describe outcomes and leave the controls to you; this regulation names them — a written information security program, encryption of personal information in transit and on portable devices, and specific contractual terms flowed down to service providers. That last point reaches us as your vendor, which is why we plan for it at contracting rather than at review.
Yes, with the access model and audit trail designed first. Research data carries provenance and consent constraints that are separate from HIPAA, and the systems that get this wrong usually did so by treating them as the same problem.