HIPAA-aware by design
BAA-ready, role-based access, encrypted storage, and detailed audit trails on every record.
Security
Every record on 31M is encrypted, isolated, role-gated, and audit-logged. Here’s how.
BAA-ready, role-based access, encrypted storage, and detailed audit trails on every record.
Independent annual audit covering security, availability, and confidentiality controls.
TLS 1.2+ in transit and AES-256 at rest. Customer data is logically isolated per organization.
Granular permission sets, time-bound elevated access, and full change history.
The program
Annual SOC 2 Type II covering security, availability, and confidentiality controls.
Business Associate Agreement signed with every customer that handles PHI.
TLS 1.2+ in transit, AES-256 at rest. Customer data is logically isolated per organization.
Continuous dependency scanning, quarterly penetration tests, and a coordinated disclosure policy.
Granular role-based access, time-bound elevated access, and detailed administrator change history.
Every read, write, and export is logged with actor, target, and timestamp — and is exportable.
Documentation
Customers and prospects under NDA can request our latest SOC 2 report, security questionnaire responses, and BAA template.
For SOC 2 reports, penetration-test summaries, or security questionnaires, please get in touch and we’ll route you to our security team.
We answer security questionnaires within five business days.