How we protect the compliance data you trust us with — because a compliance vendor with weak security is a punchline.
Why this page exists
If you are evaluating SuperHIPAA, someone on your team — probably you — has to answer the question “can we trust this vendor with information about our compliance gaps?” That is a fair question, and it deserves a better answer than a page of badges. Compliance data is unusually sensitive: it describes exactly where your organisation is weakest. A vendor that holds a map of your gaps needs to hold it carefully.
This page is the summary. The pages linked from it — infrastructure, encryption, availability, subprocessors, privacy, and responsible disclosure — carry the detail. If something you need is missing, ask us directly rather than assuming the answer; the fastest route is the security contact at the bottom of this page.
How we think about security
Three principles shape every control decision we make:
Least data. We collect the minimum needed to run the service. Data we never hold is data we can never leak, and several of our product decisions — what we ask you to upload, what we derive instead of store — follow from that.
Least access. Access to production systems and customer data is role-based, granted on need, reviewed on a defined cadence, and revoked when the need ends. Nobody at SuperHIPAA has standing access to your workspace contents as a convenience.
Assume audit. We build as if every action will be reviewed later, because in a compliance product it probably will be. Administrative and access events are logged, and logs are retained and protected as evidence, not as an afterthought.
What we commit to
The specific, verifiable control statements below are maintained by our security team and updated whenever the underlying facts change:
- All customer data is encrypted in transit (TLS 1.2+) and at rest (AES-256), with keys held in AWS KMS and rotated annually.
- SSO and MFA are enforced for all staff, access is role-based and reviewed quarterly, and background checks run on hire.
- The service is hosted on AWS in US regions, targets 99.9% monthly uptime, and is penetration-tested annually by an independent third party with continuous automated vulnerability scanning in between.
Where a commitment here appears to conflict with a signed agreement, the agreement wins. This page is a summary, not a contract.
The programme behind the page
A security page is only as good as the programme it describes. Ours includes the elements a reviewer would expect to find:
- Named ownership — a specific person is accountable for the security programme, not a shared inbox.
- Written policies — reviewed on a defined cycle and acknowledged by every employee. We run our own compliance programme in our own product, which keeps us honest about how usable it is.
- Workforce screening and training — background checks where lawful, security training at onboarding and on a recurring schedule.
- Vendor review — every subprocessor is risk-assessed before onboarding and listed publicly on the subprocessors page.
- Independent testing — external penetration testing on a defined cadence (annually, supplemented by continuous automated vulnerability scanning), with findings tracked to closure.
- Incident response — a documented plan with defined severity levels, escalation paths, and customer notification commitments that meet or exceed what our BAA requires.
What we will not claim
You will not find the phrase “HIPAA certified” anywhere on this site, because no such certification exists — HHS does not certify vendors, and any company presenting one is telling you something useful about their honesty. What we can honestly say is that we operate as a business associate under HIPAA, we sign a BAA with every customer, and we maintain the administrative, physical, and technical safeguards the Security Rule requires of us. Independent audit reports, listed below, are how you verify that rather than take our word for it.
Documentation available on request
- SOC 2 Type II report (under NDA)
- Penetration test summary
- Business Associate Agreement
- Architecture and data flow diagram
- Completed CAIQ / SIG Lite
Request any of these through the trust package form on this page. NDA-gated documents ship after a signature; everything else ships as quickly as we can manage. If your procurement process uses its own questionnaire format, send it — we answer bespoke questionnaires rather than pointing you back at the CAIQ and hoping.
Questions
Security questions go to [email protected] and get a human answer within one business day. That is a commitment we take seriously: security reviews stall when vendors go quiet, and a stalled review helps nobody. If your question needs input from engineering or legal, we will say so and give you a realistic date rather than a holding reply that pretends to be an answer.