Security
Security your agency can stand behind.
Trustora is built on HIPAA-eligible AWS infrastructure, with encryption in transit and at rest, role-based access, a one-time code on every login, and an append-only audit log kept for seven years.
HIPAA-alignedBAA availableHIPAA-eligible AWS7-year audit log
Infrastructure security
- Built on HIPAA-eligible AWS services
- AES-256 encryption at rest
- TLS 1.3 encryption in transit
- Edge protection with a web application firewall
- Private database with no public internet access
- Automated encrypted backups with point-in-time recovery
Authentication and access
- Email, password, and a one-time code on every login
- Managed identity provider, so passwords never touch our servers
- Configurable session timeout per agency
- Role-based access for every job, configurable to your agency
- Field-level access, so billing staff cannot read clinical note content
- Multi-tenant isolation at the database, API, cache, and storage layers
PHI protection
- Engineered to keep PHI out of URLs, logs, error messages, and notifications
- Minimum-necessary access enforced by role
- Continuous session and anomaly monitoring
- Bulk-export alerts when many records are exported at once
- After-hours PHI access alerts
- Alerts when staff access clients not assigned to them
Audit and recordkeeping
- Append-only audit log with SHA-256 chaining (tamper-evident)
- 7-year retention
- Every login, data access, export, and approval is logged
- One-click DHS audit binder
- Auditor-ready compliance reports
- Workforce credential monitoring and expiration alerts