Defense-in-depth security architecture designed for healthcare's most demanding requirements. Every layer hardened, every access logged, every breach scenario planned.
Six pillars of enterprise security, each implemented in depth.
AES-256-GCM at rest and TLS 1.3 in transit, both provided by the hosting platform. Selected PHI fields are encrypted at the application layer. Keys are held in the platform's secret store; there is no customer-managed KMS rotation schedule today.
Role-based access control (RBAC) with attribute-based policies (ABAC). MFA mandatory for all PHI-accessible sessions. 15-minute session timeout.
No implicit trust. Every request verified: identity, device, location, and time context. mTLS for service-to-service communication.
Insert-only audit logging for PHI access (database trigger). User identity, timestamp, resource, action, and outcome recorded.
Incidents are reviewed and handled by the engineering team; no 24/7 SOC service and no contractual detection or containment times are offered today. A breach of unsecured PHI is notified to affected individuals without unreasonable delay and no later than 60 days, per 45 CFR §164.404.
Third-party penetration testing is planned before general availability; no engagement has been completed yet and no report is available.
AES-256-GCM
At-Rest Encryption
TLS 1.3
In-Transit Encryption
FLE
Field-Level Encryption
RBAC + ABAC
Access Control
MFA
Multi-Factor Auth
mTLS
Service Mesh
WAF
Web Application Firewall
CSPM
Cloud Security Posture
Log Export
JSONL/CSV export (module, not enabled)
DLP
Data Loss Prevention
We operate a responsible disclosure program for security researchers. Vulnerabilities are acknowledged within 24 hours. Open security request. 24-hour acknowledgment
Our security team is available to answer questions, provide documentation, and support your vendor risk assessment.
Compliance Status
How the platform is built and what independent review has examined
Security Transparency We publish our security controls, audit status, and incident history to provide full transparency to our enterprise customers.