CUBE OneCare maintains a continuously evaluated security posture across 8 control domains. Each check runs against live production data — no manual attestations, no self-reported scores.
All stored artifacts have SHA-256 integrity hashes. AES-256 encryption for data at rest.
Active access grants are bound to specific email domains. Unregistered domains are blocked.
Critical configuration and access actions are recorded in the append-only audit log. The enterprise audit-log module supports SHA-256 hash chaining but is not enabled in the running product; the PHI access log is insert-only.
SAML 2.0 and OIDC federation with automatic SCIM user provisioning and deprovisioning.
Audit logs retained for minimum 90 days. Configurable retention policies per organization.
Structured incident response with defined SLAs. Open → Acknowledged → Mitigating → Resolved → Closed.
Active NDA, DPA, and BAA templates with version control and acceptance tracking.
All changes follow formal approval workflow with mandatory rollback plans.
The overall score is calculated as the percentage of checks that pass across all evaluated domains. Checks marked "not evaluated" (e.g., no SSO configured) are excluded from the denominator.
Request the full security assessment pack including posture results, compliance framework mapping (SOC 2 / ISO 27001 / HIPAA), and automated evidence.
View Compliance Pack →