Trust & Safety

Security at StagesRx

Healthcare data is among the most sensitive information that exists. We treat its protection as a core product requirement, not an afterthought.

HIPAA Compliant
Encrypted at rest & in transit
Tenant-isolated data
Append-only audit logs

Encryption everywhere

All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Database backups are encrypted with separate key management. Encryption keys are rotated on a scheduled basis.

HIPAA-compliant infrastructure

Our platform is built on cloud infrastructure with a signed Business Associate Agreement (BAA). PHI is logically isolated per tenant. No PHI is ever written to application logs.

Access controls

Role-based access control (RBAC) restricts data access to authorized users only. Administrative access requires multi-factor authentication. Access is reviewed and revoked immediately upon offboarding.

Audit logging

All data access and modifications are recorded in an append-only audit log with timestamps and user attribution. Audit logs are tamper-evident and retained for a minimum of seven years.

Vulnerability management

Dependencies are monitored for known CVEs with automated alerts. We perform regular code reviews with security focus and address critical vulnerabilities on an expedited timeline.

Authentication security

Patient authentication uses one-time verification codes with short TTLs. Staff credentials use bcrypt hashing with a high work factor. Password reset tokens are SHA-256 hashed and expire within one hour.

Network security

Production services run in a private network with strict ingress rules. Public endpoints are protected against common web vulnerabilities. API rate limiting is enforced to prevent abuse.

Backups and recovery

Database backups run on an automated schedule with point-in-time recovery capability. Backups are stored in a separate region. Recovery procedures are tested periodically.

Responsible Disclosure

We welcome reports from security researchers and the broader community. If you discover a potential security vulnerability in our platform, please report it to us before disclosing it publicly. We will acknowledge receipt within two business days and work with you to understand and resolve the issue promptly.

Please do not access, modify, or delete data belonging to other users; do not perform denial-of-service testing; and do not use automated scanners against production systems without prior written permission.

Report a vulnerability →

Our Data Commitments

We never sell your data

Patient data and PHI are never sold, rented, or shared with third parties for advertising or commercial purposes.

Minimum necessary access

We follow the HIPAA minimum necessary standard — employees and systems access only the PHI required to perform their specific function.

Sub-processor accountability

Any third-party service providers who process PHI on our behalf are contractually bound by a BAA and undergo security review before onboarding.

Breach notification

In the event of a breach affecting PHI, we will notify affected covered entities as required by HIPAA and cooperate fully with any investigation.

Questions about security?

Compliance teams, enterprise buyers, and security professionals are welcome to reach out. We can provide additional documentation on request, including details on our infrastructure architecture and data handling practices.

Contact security team →