Trust Center

Infrastructure

Hosting regions, network architecture, tenancy model, and change management.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

Hosting regions, network architecture, tenancy model, and change management.

Where the service runs

SuperHIPAA is hosted on Amazon Web Services (AWS), under a signed BAA with the provider, in US regions. The current region list is us-east-1 (N. Virginia) as the primary region, with us-west-2 (Oregon) holding encrypted backup replicas for disaster recovery. All customer data — including backups and replicas — resides in the United States, and movement outside the US does not happen without your agreement in writing.

We deliberately build on a major cloud provider rather than our own hardware. The physical safeguards HIPAA cares about — facility access, media handling, environmental controls — are areas where a hyperscale data centre operator is simply better resourced than any company our size could be, and their compliance attestations are independently audited and publicly documented.

Tenancy model

The service is multi-tenant with logical isolation:

  • Every piece of customer data carries a tenant identifier, and isolation is enforced at both the application layer and the database policy layer (row-level security) — not left to application code remembering to add a WHERE clause.
  • Tenant isolation is specifically exercised in penetration testing, because cross-tenant access is the failure mode that matters most in a multi-tenant compliance product.
  • A dedicated single-tenant deployment is available on enterprise plans for customers whose policies require stronger separation.

Network architecture

  • Production runs in private network segments; databases and internal services are not reachable from the public internet.
  • Ingress passes through a managed edge with TLS termination, DDoS absorption, and a web application firewall.
  • Egress from production is restricted and monitored — data leaving the environment is a controlled event, not a default capability.
  • Administrative access requires SSO with enforced MFA via a zero-trust access proxy; there is no direct SSH from the open internet.

Change management

Most incidents are self-inflicted, so how changes reach production is a security control in its own right:

  • All infrastructure is defined as code and changed through reviewed pull requests — no hand-edited production consoles.
  • Every deploy passes automated tests and at least one human review before it ships.
  • Deploys are logged, attributable, and reversible; rollback is a routine operation, not an emergency procedure.
  • Emergency changes follow a documented fast path that preserves review after the fact rather than skipping it entirely.

What we commit to

  • Production runs on AWS in US regions — us-east-1 primary, us-west-2 backup — and all customer data resides in the United States.
  • Administrative access requires SSO with enforced MFA, is role-based, and is reviewed quarterly.
  • An independent third party penetration-tests the environment annually, with automated vulnerability scanning running continuously between tests.

Monitoring and hardening

  • Hosts and containers are built from hardened, minimal images and rebuilt regularly rather than patched in place indefinitely.
  • Vulnerability scanning runs on a defined cadence across infrastructure and dependencies, with remediation timelines tied to severity (critical within 7 days, high within 30, medium within 90).
  • Centralised logging and alerting cover authentication events, privilege changes, and anomalous access patterns, feeding the incident response process described on the security overview page.

What to verify rather than trust

A sensible reviewer should not take an architecture description on faith. The SOC 2 report covers the operating effectiveness of these controls over a period, not just their design; the penetration test summary shows what an adversarial tester found; and the architecture diagram, available under NDA, shows the real topology rather than a marketing simplification. All three are requestable below.

Documentation available on request

  • SOC 2 Type II report (under NDA)
  • Penetration test summary
  • Business Associate Agreement
  • Architecture and data flow diagram
  • Completed CAIQ / SIG Lite

Questions

Security questions go to security@superhipaa.com and get a human answer within one business day. Questions about region availability or data residency for a specific deal are welcome — asking before procurement starts is cheaper for everyone than discovering a residency conflict at contract stage.

Questions

Will you sign our BAA instead of yours?

Usually yes. Send it over — we redline rather than refuse.

Can we get your SOC 2 report?

Yes, under NDA. Request it through the trust package form on this page.

Where is our data stored?

Region is selectable at provisioning. See the Infrastructure page for the current list.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo