HIPAA-aware by design
BAA-ready, role-based access, encrypted storage, and detailed audit trails on every record.
Security
Every record on 31M is encrypted, isolated, role-gated, and audit-logged. Here’s how.
BAA-ready, role-based access, encrypted storage, and detailed audit trails on every record.
Independent annual audit covering security, availability, and confidentiality controls.
TLS 1.2+ in transit and AES-256 at rest. Customer data is logically isolated per organization.
Granular permission sets, time-bound elevated access, and full change history.
The program
Annual SOC 2 Type II covering security, availability, and confidentiality controls.
Business Associate Agreement signed with every customer that handles PHI.
TLS 1.2+ in transit, AES-256 at rest. Customer data is logically isolated per organization.
Continuous dependency scanning, quarterly penetration tests, and a coordinated disclosure policy.
Granular role-based access, time-bound elevated access, and detailed administrator change history.
Every read, write, and export is logged with actor, target, and timestamp, and is exportable.
Documentation
Customers and prospects under NDA can request our latest SOC 2 report, security questionnaire responses, and BAA template.
For SOC 2 reports, penetration-test summaries, or security questionnaires, please get in touch and we’ll route you to our security team.
We answer security questionnaires within five business days.