Skip to main content
Our security

How we protect your data

It would be strange to advise on security and be vague about our own. Here is exactly how we protect client information.

Practices

What we commit to

Minimum necessary by default

We ask for configuration details, policies, and evidence. We do not ask for patient records, and we do not need production access to do the work.

No protected health information in reports

Findings describe systems and controls. If a screenshot would contain patient data, it is redacted before it enters any deliverable.

Encrypted collection and storage

Documents move through an encrypted client portal, not email attachments, and are encrypted at rest for the life of the engagement.

Short retention

Working files are deleted after the engagement closes on a defined schedule. Final deliverables are retained only as long as your agreement specifies.

Business associate agreements

We sign a BAA before any engagement where incidental exposure to protected health information is possible.

Access limited to the engagement team

Multi-factor authentication on every account, unique credentials, and no shared logins. Access is removed when an engagement ends.

FAQ

Data handling questions

Questions about how we handle data?

A 30-minute scoping call covers your setup, your deadlines, and what a fixed-fee engagement would look like.

Book a scoping call