SECURITY
Security at Trusted
We hold ourselves to the highest standards in healthcare, data security, and privacy. Here's how.
On this page
Organizational Security
-
Third-Party Penetration Testing
We perform an independent third-party penetration test at least annually to ensure that the security posture of our services is uncompromised.
-
Confidentiality
All team members are required to sign and adhere to an industry standard confidentiality agreement prior to their first day of work.
-
Compliance
We are ISO 27001:2022 and SOC 2 Type 1 compliant. If you are a customer and need the report or more details, please contact us at security@trustedhealth.com.
Cloud Security
-
Cloud Infrastructure Security
All of our services are hosted with Amazon Web Services (AWS) and Heroku. They employ a robust security program with multiple certifications.
-
Data Hosting Security
All of our data is hosted on Amazon Web Services and Heroku databases, located in the United States.
-
Vulnerability Scanning
We perform vulnerability scanning and actively monitor for threats.
-
Logging and Monitoring
We actively monitor and log various cloud services.
-
Business Continuity and Disaster Recovery
We use our data hosting provider’s backup services to reduce any risk of data loss in the event of a hardware failure. We utilize monitoring services to alert the team in the event of any failures affecting users.
-
Incident Response
We have a process for handling information security events which includes escalation procedures, rapid mitigation and communication.
Access Security
-
Permissions and Authentication
Access to cloud infrastructure and other sensitive tools is limited to authorized employees who require it for their role. Where available, we use single sign-on (SSO), two-factor authentication (2FA) and strong password policies.
-
Least Privilege Access Control
We follow the principle of least privilege with respect to identity and access management.
-
Quarterly Access Reviews
We perform quarterly access reviews of all team members with access to sensitive systems.
-
Password Requirements
All team members are required to adhere to a minimum set of password requirements and complexity for access.
-
Password Managers
All company issued laptops utilize a password manager for team members to manage passwords and maintain password complexity.
Vendor and Risk Management
-
Annual Risk Assessments
We undergo at least annual risk assessments to identify any potential threats, including considerations for fraud.
-
Vendor Risk Management
Vendor risk is determined and the appropriate vendor reviews are performed prior to authorizing a new vendor.
We're here to help
Have a security question, need our SOC 2 report, or want to report a vulnerability? Our security team can help. To report a vulnerability, please include steps to reproduce so we can triage quickly.