Security & Compliance · Advanced

HIPAA & SOC2 Type II Architecture & Security Controls

Detailed overview of encryption at rest, tokenized patient identifiers, continuous audit logging, and perimeter defense.

Author: Security & Compliance Office•8 min read•Last Updated: Jul 2026
HIPAA & SOC2 Type II Architecture & Security Controls

1. Data Encryption & Tokenization

All customer and patient data is encrypted in transit using TLS 1.3 with strict cipher suites, and at rest using AES-256 with KMS managed keys.

Personally Identifiable Information (PII) and Protected Health Information (PHI) are tokenized at the ingestion perimeter before storage.

2. Continuous Audit Logging & Immutability

All access attempts, administrative configuration modifications, and data export operations generate immutable audit log records.

Logs are continuously replicated to write-once-read-many (WORM) storage buckets to ensure non-repudiation during compliance audits.

Related Knowledge Guides

View all guides→