Trust Center

Security is part of the product.

Predict. Prevent. Protect.

Paladyn handles some of the most sensitive data in healthcare, so we engineer for protection the same way we engineer for prevention. This page lays out how we secure data, how we stay resilient, and exactly where we are on our path to formal certification — including what is in place today and what is still in progress.

Our security model at a glance

PHI isolation

Protected health information lives only inside our HIPAA-eligible AWS environment, behind a secure SFTP intake. It never touches this website, email, file shares, logs, or AI surfaces.

Encryption everywhere

Data is encrypted in transit (TLS) and at rest (AWS KMS-managed keys on storage and databases). Backups are encrypted on every leg.

Least-privilege identity

One identity authority mapped to Microsoft Entra ID governs access with role-based, least-privilege permissions — no scattered per-application logins.

Multi-factor authentication

MFA (PBKDF2 password hardening plus time-based one-time codes, RFC 6238) is built across the platform and enforced where access is sensitive.

Tamper-evident audit

Security-relevant events are written to append-only, hash-chained audit logs, so any change to the record is detectable.

3-2-1-1-0 backups

Three copies, two media, one off-site, one offline and immutable (write-once S3 Object Lock in a separate AWS account), with zero errors on tested restores.

Where PHI lives — and where it never goes

The simplest way to protect patient data is to keep it in one controlled place. All protected health information (PHI) is processed and stored inside a HIPAA-eligible AWS environment, reached only through a secure SFTP intake. PHI is never written to this website, to email, to document or file-sharing systems, to application or operational logs, or to any AI surface. Most of our tools are built PHI-free by design and reference sensitive records only by opaque identifier. Our cloud infrastructure is HIPAA-eligible and covered by a signed Business Associate Agreement.

How we secure and protect data

Encryption & key management

Traffic is protected with TLS in transit. Storage and databases are encrypted at rest using managed keys (AWS KMS), and every backup leg is encrypted. Production secrets are read from the environment or a secrets store — never committed to code.

Identity & access

Access runs through a single identity authority mapped one-to-one to Microsoft Entra ID, with role-based, least-privilege permissions and multi-factor authentication. There are no per-application employee password tables and no parallel identity silos.

Audit & monitoring

Security-relevant events are recorded in append-only, hash-chained audit logs that make tampering detectable. Operational logging is PHI-safe by construction, and change control and security monitoring are governed centrally.

Resilience & redundancy — 3-2-1-1-0

We follow a 3-2-1-1-0 backup standard: 3 copies of data, on 2 kinds of media, with 1 copy off-site and 1 copy offline and immutable — write-once, read-many storage (S3 Object Lock in compliance mode) held in a separate AWS account so it cannot be altered or deleted, even by an administrator. The final 0 means zero errors on a tested restore: a backup only counts once we have verified it restores.

Safe change

Database schema changes ship as versioned, forward-only migrations recorded in a tamper-evident ledger, and a verified backup is always taken before a change. Deployments are test-gated and roll back automatically on failure.

Secure delivery

Cloud releases use short-lived OIDC tokens with no stored AWS keys; on-prem releases are cryptographically signed. Every deploy is logged and reversible to a known-good version.

Compliance & certifications — where we stand

We believe in being precise about this. Today Paladyn operates as a HIPAA Business Associate. We are building toward HITRUST certification and a SOC 2 Type II examination, and the underlying controls those frameworks require are already implemented and running. We are not yet certified; here is an honest accounting of both sides.

In place today

  • Operating as a HIPAA Business Associate, with a signed Business Associate Agreement in place with our cloud infrastructure provider
  • Documented PHI data-flow isolation — PHI confined to a HIPAA-eligible AWS environment behind a secure SFTP intake
  • Encryption of data in transit and at rest, with managed keys
  • Centralized identity with least-privilege, role-based access, backed by Microsoft Entra ID
  • Multi-factor authentication built across the platform
  • Append-only, hash-chained audit logging with PHI-safe operational logging
  • 3-2-1-1-0 backups including offline, immutable copies in a separate account, with tested restores
  • Controlled, forward-only schema change with a verified backup taken before any change
  • Keyless cloud deployment (short-lived OIDC tokens, no stored access keys) and signed on-prem deployment with automatic rollback
  • PHI-free architecture for every tool that does not require patient data

In progress & on the roadmap

  • SOC 2 Type II examination
  • HITRUST CSF certification, beginning with the entry-level (e1) path
  • Finalizing the formal information-security policy set
  • Rolling out single sign-on (Microsoft Entra) across all tools
  • Expanding continuous security monitoring and formal change governance

"Built for HITRUST" and "SOC 2 on the roadmap" describe our engineering and certification trajectory, not a current certification. A more detailed security and HITRUST-readiness overview is available to prospective clients under NDA — just ask.

Vendors & subprocessors

We keep the set of systems that can touch sensitive data deliberately small. Our cloud infrastructure (AWS) is HIPAA-eligible and covered by a signed Business Associate Agreement; identity is handled through Microsoft Entra. Any subprocessor that could process PHI is governed by a Business Associate Agreement, and PHI is never routed into general business tools such as email, file sharing, or AI services.

See where prevention pays off.

Request a revenue cycle assessment and we'll show how Paladyn would apply to your denials, AR, and payer mix. We're also taking on a small number of design partners.

Request an assessment