Compliance
HIPAA
CompliantSOC 2 Type II
In ProgressGDPR
CompliantResources
Controls
28/31 implementedInfrastructure Security
- Data encrypted at rest (AES-256)
- Data encrypted in transit (TLS 1.2+)
- Multi-tenant data isolation
+ 7 more
Product Security
- Authentication required for all endpoints
- Multi-factor authentication
- Role-based access control (RBAC)
+ 4 more
Organizational Security
- Security awareness training
- Vendor security assessments
- Incident response plan
+ 3 more
Internal Security Procedures
- Code review required for all changes
- Automated security scanning in CI/CD
- Dependency vulnerability scanning
+ 5 more
