Security

Security your agency can stand behind.

Trustora is built on HIPAA-eligible AWS infrastructure, with encryption in transit and at rest, role-based access, a one-time code on every login, and an append-only audit log kept for seven years.

HIPAA-alignedBAA availableHIPAA-eligible AWS7-year audit log

Infrastructure security

  • Built on HIPAA-eligible AWS services
  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • Edge protection with a web application firewall
  • Private database with no public internet access
  • Automated encrypted backups with point-in-time recovery

Authentication and access

  • Email, password, and a one-time code on every login
  • Managed identity provider, so passwords never touch our servers
  • Configurable session timeout per agency
  • Role-based access for every job, configurable to your agency
  • Field-level access, so billing staff cannot read clinical note content
  • Multi-tenant isolation at the database, API, cache, and storage layers

PHI protection

  • Engineered to keep PHI out of URLs, logs, error messages, and notifications
  • Minimum-necessary access enforced by role
  • Continuous session and anomaly monitoring
  • Bulk-export alerts when many records are exported at once
  • After-hours PHI access alerts
  • Alerts when staff access clients not assigned to them

Audit and recordkeeping

  • Append-only audit log with SHA-256 chaining (tamper-evident)
  • 7-year retention
  • Every login, data access, export, and approval is logged
  • One-click DHS audit binder
  • Auditor-ready compliance reports
  • Workforce credential monitoring and expiration alerts