Trust & Safety
Security at StagesRx
Healthcare data is among the most sensitive information that exists. We treat its protection as a core product requirement, not an afterthought.
Encryption everywhere
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Database backups are encrypted with separate key management. Encryption keys are rotated on a scheduled basis.
HIPAA-compliant infrastructure
Our platform is built on cloud infrastructure with a signed Business Associate Agreement (BAA). PHI is logically isolated per tenant. No PHI is ever written to application logs.
Access controls
Role-based access control (RBAC) restricts data access to authorized users only. Administrative access requires multi-factor authentication. Access is reviewed and revoked immediately upon offboarding.
Audit logging
All data access and modifications are recorded in an append-only audit log with timestamps and user attribution. Audit logs are tamper-evident and retained for a minimum of seven years.
Vulnerability management
Dependencies are monitored for known CVEs with automated alerts. We perform regular code reviews with security focus and address critical vulnerabilities on an expedited timeline.
Authentication security
Patient authentication uses one-time verification codes with short TTLs. Staff credentials use bcrypt hashing with a high work factor. Password reset tokens are SHA-256 hashed and expire within one hour.
Network security
Production services run in a private network with strict ingress rules. Public endpoints are protected against common web vulnerabilities. API rate limiting is enforced to prevent abuse.
Backups and recovery
Database backups run on an automated schedule with point-in-time recovery capability. Backups are stored in a separate region. Recovery procedures are tested periodically.
Responsible Disclosure
We welcome reports from security researchers and the broader community. If you discover a potential security vulnerability in our platform, please report it to us before disclosing it publicly. We will acknowledge receipt within two business days and work with you to understand and resolve the issue promptly.
Please do not access, modify, or delete data belonging to other users; do not perform denial-of-service testing; and do not use automated scanners against production systems without prior written permission.
Report a vulnerability →Our Data Commitments
We never sell your data
Patient data and PHI are never sold, rented, or shared with third parties for advertising or commercial purposes.
Minimum necessary access
We follow the HIPAA minimum necessary standard — employees and systems access only the PHI required to perform their specific function.
Sub-processor accountability
Any third-party service providers who process PHI on our behalf are contractually bound by a BAA and undergo security review before onboarding.
Breach notification
In the event of a breach affecting PHI, we will notify affected covered entities as required by HIPAA and cooperate fully with any investigation.
Questions about security?
Compliance teams, enterprise buyers, and security professionals are welcome to reach out. We can provide additional documentation on request, including details on our infrastructure architecture and data handling practices.
Contact security team →