Skip to main content
HomeTrust CenterSecurity
Trust Center · Security

Security program, documented in detail.

The ApiVoc security program covers eight functional domains. All controls operate on a single Microsoft Azure tenant in US regions, governed by Microsoft Entra ID, and continuously monitored through Drata.

AES-256 at rest TLS 1.2+ in transit MFA enforced
Encryption

At rest and in transit, end to end.

Encryption is enforced at every layer where data is stored or transmitted. AES-256 at rest, TLS 1.2 or higher in transit. Key management runs through Azure Key Vault.

At rest

Database
Transparent Data Encryption (TDE)
AES-256
Azure-managed
Application storage
Storage Service Encryption
AES-256
Customer-managed via Azure Key Vault
Backups
Encrypted backups
AES-256
Azure Key Vault
Secrets
Azure Key Vault
AES-256-GCM
HSM-backed

In transit

External (customer/integrator → ApiVoc)
TLS 1.2+
AES-256-GCM
TLS 1.0/1.1 disabled. Strong ciphers only.
Internal (service-to-service)
mTLS / private endpoints
AES-256-GCM
Azure Private Link where supported.
Administrative access
TLS 1.2+ over VPN
AES-256-GCM
Bastion access only. No public RDP/SSH.
Domains

Eight domains, all owned.

Each domain has documented policies, designated owners, technical controls, and evidence collected continuously through Drata.

/ 01

Identity & access

Microsoft Entra ID with MFA enforced for all workforce accounts. Role-based access control. Just-in-time elevation for privileged operations. Quarterly access reviews. Termination removes access same-day.

/ 02

Network security

Single Azure tenant, US regions only. Azure Private Link for service-to-service traffic where supported. WAF on public endpoints. No public RDP/SSH; bastion-only administrative access.

/ 03

Data protection

AES-256 encryption at rest across databases, storage, and backups. TLS 1.2+ in transit with strong ciphers. Azure Key Vault for key management. Data classification and handling procedures documented.

/ 04

Application security

Secure SDLC with code review on every change. Static and dependency analysis in CI. Secrets management via Azure Key Vault. Vulnerability management aligned with CVSS-based remediation timelines.

/ 05

Logging & monitoring

Centralized logging through Azure Monitor and Log Analytics. Authentication, access, and PHI disclosure logging. Continuous compliance monitoring through Drata. Anomaly review on a documented cadence.

/ 06

Incident response

Documented incident response plan with defined roles, severity levels, and communication procedures. Integrated with HIPAA breach response. Tabletop exercises conducted regularly.

/ 07

Business continuity

Documented BCP and DR procedures. RTO and RPO defined per system criticality. Backups tested. Annual tabletop exercise. Multi-region capability where required.

/ 08

Vendor risk management

Vendor risk assessment before onboarding. BAA execution before any PHI exchange. Annual reviews of critical vendors. Documented offboarding procedures.

Service-level commitments

The numbers we work to.

Internal SLAs that govern how the security program operates day-to-day. These are the same numbers we report against in audits, vendor questionnaires, and customer reviews.

Critical vulnerability remediation

< 7 days

CVSS 9.0+ or actively exploited. Tracked to closure with executive visibility.

High vulnerability remediation

< 30 days

CVSS 7.0–8.9. Standard remediation cycle through change management.

Production access provisioning

Same business day

For approved requests. Includes role-based access review at provisioning time.

Access termination

< 1 business day

On workforce departure or role change. Most terminations execute within hours.

Incident triage

< 1 hour

For confirmed security incidents. Integrated with on-call rotation.

BA breach notification

< 60 days

BA → CE notification per HIPAA §164.410. Notification often substantially earlier.

Security contact

Reporting and inquiries.

For security questionnaires, vulnerability reports, or any security-program inquiry, route directly to our CISO.

CISO

Nick Randall
CISO · Privacy & Compliance Officer
480-888-6820

For vulnerability reports

Send details directly to Nick. Acknowledged within one business day. Full response timing depends on severity. We work in good faith with security researchers and don't pursue legal action against good-faith disclosure.