How we protect your data
It would be strange to advise on security and be vague about our own. Here is exactly how we protect client information.
What we commit to
Minimum necessary by default
We ask for configuration details, policies, and evidence. We do not ask for patient records, and we do not need production access to do the work.
No protected health information in reports
Findings describe systems and controls. If a screenshot would contain patient data, it is redacted before it enters any deliverable.
Encrypted collection and storage
Documents move through an encrypted client portal, not email attachments, and are encrypted at rest for the life of the engagement.
Short retention
Working files are deleted after the engagement closes on a defined schedule. Final deliverables are retained only as long as your agreement specifies.
Business associate agreements
We sign a BAA before any engagement where incidental exposure to protected health information is possible.
Access limited to the engagement team
Multi-factor authentication on every account, unique credentials, and no shared logins. Access is removed when an engagement ends.
Data handling questions
Questions about how we handle data?
A 30-minute scoping call covers your setup, your deadlines, and what a fixed-fee engagement would look like.