Security
Verifiable. Not asserted.
Anyone can put a padlock icon on a website. What follows is the evidence behind ours — the controls, who they are audited by, where protected health information physically lives, and what happens on the worst day.
- Framework
- HIPAA · SOC 2
- Encryption
- AES-256 · TLS 1.2+
- Tenancy
- Key-isolated
- Breach notice
- 24 hours
What we are actually audited against
Note the difference between certified and aligned. We keep them separate because conflating the two is the most common overclaim in healthcare vendor security, and you will find out either way during diligence.
HIPAA
CompliantAdministrative, physical and technical safeguards under the Security Rule, plus Privacy Rule obligations as a Business Associate.
We execute a Business Associate Agreement with every covered entity before any protected health information is transmitted. Workforce training is completed at onboarding and refreshed annually.
SOC 2
Type IIIndependent audit of security, availability and confidentiality controls across an observation window.
The report is available under NDA. Ask for the current one rather than the summary — a Type II is only meaningful alongside its exceptions, and we would rather walk you through ours than have you discover them at procurement.
HITRUST CSF
AlignedControls mapped to the HITRUST Common Security Framework. Not currently certified.
We map to the framework because most of our customers are assessed against it and a shared control language shortens their diligence. We do not claim certification, and we will say so in writing.
ISO/IEC 27001
AlignedInformation security management system modelled on the standard. Not currently certified.
Our ISMS follows the Annex A control set. Certification is on the roadmap; until an accredited body has issued a certificate, this page will keep saying "aligned".
Where your data actually goes
Not “are you encrypted” — everyone says yes — but where PHI physically lives, who can reach it, and when it is destroyed.
01
Arrival
PHI reaches us over TLS 1.2+ through an SFTP endpoint, a clearinghouse integration, or a direct EHR connection. Nothing is accepted over email, and attachments sent to a person rather than a system are quarantined and reported, not processed.
02
Isolation
Each customer is a separate logical tenant with its own encryption key. There is no shared table with a customer_id column — a query that crosses a tenant boundary does not have a path to run, rather than being blocked by a filter someone could forget.
03
Processing
Work happens inside the environment. Analysts operate through a brokered virtual desktop with clipboard, printing and local storage disabled, so PHI never lands on an endpoint — including in an office we control.
04
At rest
AES-256 on every volume, snapshot and backup. Keys are held in a managed KMS with rotation, and are separable per tenant so a customer can be cryptographically severed from the platform on request.
05
Retention and destruction
Retention is set per contract, defaulting to the shorter of your policy and the statutory minimum. On termination we return your data in an agreed format and then destroy it, including backups, and issue a written certificate of destruction.
The six control families
- Encryption
- AES-256 at rest, TLS 1.3 in transit. Keys rotated on a fixed schedule and never co-located with the data they protect.
- HIPAA Compliance
- Executed BAAs, an annually reviewed Security Risk Analysis, and a documented breach-notification runbook.
- Audit Trails
- Every read and write against PHI is written to an append-only ledger with actor, purpose and timestamp.
- Secure Cloud
- Isolated tenancy, private networking, and infrastructure defined in code so drift is impossible to introduce quietly.
- Access Control
- Role-based, least-privilege access with mandatory MFA and quarterly entitlement reviews.
- Continuity
- Point-in-time recovery, geographically separated replicas, and restore drills that are actually run.
Who else can reach it
The full list. We give notice before adding to it, and you can object.
| Subprocessor | Purpose | Region | BAA |
|---|---|---|---|
| Cloud infrastructure provider | Compute, storage and managed database hosting | United States | Executed |
| Clearinghouse | Claim submission and remittance routing | United States | Executed |
| Observability platform | Application logs and performance monitoring | United States | Executed — PHI excluded by configuration |
| Transactional email provider | System notifications to named staff users | United States | Executed — no PHI in message bodies |
What happens on the worst day.
These windows are commitments, not intentions. The point of publishing them is that you can hold us to them.
SEV-1
24h
Confirmed unauthorised access to, or acquisition of, PHI.
SEV-2
72h
Suspected exposure, or a control failure that could have permitted access.
SEV-3
5d
Service disruption or degradation with no indication of data exposure.
Found something?
If you believe you have found a vulnerability, tell us before you tell anyone else and we will work the problem with you. We do not pursue legal action against researchers who act in good faith, stay within their own test data, and give us reasonable time to remediate.
sushanth3306@gmail.comRequest the full security packet
SOC 2 Type II report, penetration test summary, policy set, BAA template and completed CAIQ. Under NDA, usually the same business day.
Request the packet