Skip to main content

Security

Security, built in — not bolted on.

Security posture varies by product and maturity stage — a LIVE clinical platform and a BUILT prototype are held to different operational standards. What follows describes what the studio designs for, not a blanket certification across every product.

Encryption by Default

Products handling sensitive data are built with encryption at rest and in transit as a baseline, not an add-on.

Built for HIPAA Technical Safeguards

VitalEdge and the VSumUp Health ecosystem are architected around HIPAA technical safeguards from the ground up.

Role-Based Access Control

Multi-tenant products isolate data by organization with role-based access and the principle of least privilege.

Audit Trails

Access and changes to sensitive records are logged with timestamps and user context, for products that require it.

Interoperability & Encryption

  • HL7 / FHIR R4 support in the health ecosystem (VitalEdge, vSumUp Consult)
  • AES-256 encryption used across products handling sensitive or client data
  • TLS in transit across all live products
  • Multi-tenant data isolation enforced at the application layer

Per-Product Detail

Technology and compliance posture for each product — including what is and isn’t yet in place — is documented on that product’s own profile page.

View the portfolio

Questions about a specific product’s security posture?

Reach out directly — every request is reviewed personally, not routed through a sales queue.

Contact the Studio