Security Overview
Protecting sensitive health information is at the core of everything we build. Our platform is designed with HIPAA-aligned privacy and security controls to safeguard your data at every layer.
Encryption
- AES-256 encryption for all data at rest
- TLS 1.2+ encryption for all data in transit
- Encrypted database backups
- Secure key management with regular rotation
Access Control
- Role-based access controls (RBAC)
- Multi-factor authentication (MFA)
- Single sign-on (SSO) support
- Automatic session timeouts
- Principle of least privilege enforcement
Audit & Monitoring
- Immutable audit logging for all data access
- Real-time security event monitoring
- Automated anomaly detection
- Comprehensive activity trails for compliance reporting
Infrastructure
- Hosted on enterprise-grade cloud infrastructure
- Geographically redundant data centers
- Automated failover and disaster recovery
- Regular infrastructure patching and updates
- 99.9% uptime SLA
Application Security
- Secure software development lifecycle (SDLC)
- Regular vulnerability assessments
- Penetration testing by third-party specialists
- Dependency scanning and management
- Web Application Firewall (WAF) protection
Incident Response
- Documented incident response plan
- Breach notification within HIPAA-required timeframes
- Post-incident analysis and remediation
- Regular tabletop exercises and plan testing
Compliance & Certifications
HIPAA Alignment
Our platform is designed in alignment with HIPAA Privacy and Security Rules. We offer Business Associate Agreements (BAAs) to all eligible customers and implement administrative, physical, and technical safeguards required to protect PHI.
Learn more about our BAA →Data Privacy
We are committed to transparency in how we collect, use, and protect your personal information. Our data handling practices are documented in our Privacy Policy.
View our Privacy Policy →Independent Assessment
We recommend independent third-party assessment for formal compliance certification. We are happy to provide security documentation and answer due-diligence questionnaires upon request.
Responsible Disclosure
If you believe you have discovered a security vulnerability in our platform, please report it responsibly. We appreciate the efforts of security researchers and will work with you to address any verified issues promptly.
Report a vulnerability:
Email: customer@aurinsolutions.com
Please include a detailed description of the vulnerability and steps to reproduce.