Enterprise-Grade Security

Built from the first line of code with security as a core architectural requirement for protected health information. Not bolted on — baked in.

ONC 2020 Certified
HIPAA Compliant
SOC 2 Type II
ISO 27001
Annual Penetration Tested
Bug Bounty Program

Security Framework

Encryption

Every byte of patient data is encrypted at rest and in transit with military-grade algorithms.

  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • Customer-managed encryption keys (BYOK)
  • End-to-end encryption for PHI data

Access Control

Granular, role-based access controls ensure providers only see what they need to see.

  • RBAC with 25+ predefined roles
  • SSO/SAML 2.0 integration
  • Multi-factor authentication (MFA)
  • Session timeout & lock management

Auditing & Monitoring

Complete activity logging with immutable audit trails for all PHI access and changes.

  • Immutable audit trails
  • Real-time anomaly detection
  • Privilege escalation monitoring
  • SIEM integration ready

Vulnerability Management

Continuous monitoring with automated patching and annual third-party penetration testing.

  • Annual pentest by CERTIFIED ethical hackers
  • Continuous vulnerability scanning
  • Automated security patch deployment
  • Bug bounty program active

Infrastructure

Deployed on enterprise cloud infrastructure with geo-redundancy and disaster recovery.

  • AWS/Azure/GCP multi-region
  • 99.99% uptime SLA
  • Geo-redundant failover
  • On-premise deployment option

Compliance & Legal

BAAs, data processing agreements, and compliance documentation available on demand.

  • HIPAA BAA included
  • DPA available for EU data
  • Data residency controls
  • Annual compliance attestation

Encryption in Detail

Data at Rest

All database volumes use AES-256 encryption with customer-managed keys. PostgreSQL TDE and AWS EBS encryption provide defense-in-depth. Backup volumes are encrypted identically.

Data in Transit

All API communications use TLS 1.3 with strong cipher suites. Internal service-to-service communication uses mutual TLS (mTLS) with certificate rotation.

Key Management

Customers can use their own encryption keys via BYOK through AWS KMS, Azure Key Vault, or GCP Cloud KMS. Key rotation is automated and auditable.

PHI Protection

Protected Health Information is encrypted at the application layer before reaching the database. Even database administrators cannot access unencrypted PHI. Full decryption requires multi-party authorization.

AI WFM Security Integration

The AI WFM workforce module shares AI EHR's security architecture. All data exchanged between platforms is encrypted with AES-256 at rest and TLS 1.3 in transit. The integration is covered under AI EHR's existing BAA — no additional agreements required. Provider credential tracking and shift assignment data flow through the same zero-trust network architecture.

Platform Uptime

99.99%

Measured over trailing 12 months. Backed by 99.99% uptime SLA with financial penalties for underperformance.

365 days
Tracked
0
Planned Downtime (YTD)
3.8 min
Max Unplanned (2026)