Trust Center

Built-in Security you Can Trust.

Healthcare data deserves defense-in-depth, not disclaimers. This page is how we run BytePad: a live security scorecard, independent certifications, per-tenant isolation by architecture, and the documentation your review team will ask for.

Scorecard measured continuously across the estate — not asserted annually.

HITRUST r2 SOC 2 Type II ISO 27001:2022 HIPAA

Live Security Scorecard

Measured, not asserted.

Most trust pages show you last year's audit. Ours shows you today's posture: continuous control monitoring across every endpoint and environment, rolled into one score your security team can interrogate.

Least Privilege Defense-in-Depth Consistent Application Continuous Improvement
98/100
Security Score

Continuously verified

All controls passing across the estate — measured, not asserted.

0Active P1 Incidents
<24hMean Time to Patch
24×7Endpoints Monitored
All Controls Passing

Certifications & Frameworks

Independently examined.

Third-party certifications and the control frameworks BytePad operations map to — with the posture stated honestly, badge by badge.

Certified

HITRUST r2

The most rigorous certification in healthcare security — a validated assessment across the full control set, covering the platform and the operations behind it.

Attested

SOC 2 Type II

Independent attestation that security, availability and confidentiality controls operate effectively over time — not just on audit day.

Certified

ISO 27001:2022

A certified information security management system — risk assessment, treatment and improvement run as a discipline, on the current 2022 revision.

Compliant

HIPAA

Privacy, Security and Breach Notification rules built into how the platform handles PHI — with BAAs executed for every covered engagement.

Aligned

NIST SP 800-53

Controls mapped to the NIST SP 800-53 catalog — the common language federal and government-adjacent security reviews expect.

Aligned

CMMC Level 2

Practices aligned to CMMC Level 2 for engagements that touch controlled unclassified information in the defense supply chain.

Supported

DoD RMF

Deployments supporting the DoD Risk Management Framework authorization path — including Azure Government and AWS GovCloud hosting.

Certification letters, attestation reports and control mappings are available under NDA — request documentation.

Security Principles

Four principles, consistently applied.

Every control on this page traces back to one of four principles. They are how we make security decisions when the checklist runs out.

Least Privilege

Every role, service and query gets the minimum access it needs — RBAC/ABAC enforced at the API seam, reviewed and re-certified on a schedule.

Defense-in-Depth

AES-256 at rest, TLS 1.2+ in transit, network isolation, and audit logging at every layer. No single control is ever the whole plan.

Consistent Application

The same controls run in every environment — commercial, government or hybrid. There is no "lite" security tier and no unmanaged exception path.

Continuous Improvement

Continuous control monitoring, a <24h mean time to patch, and recurring independent assessment — posture that gets stronger between audits, not staler.

Tenant Isolation

Isolation by architecture, not by filter.

Many platforms separate tenants with a column and a WHERE clause. BytePad separates them with infrastructure: each tenant gets its own database, its own blob storage, and its own encryption key.

Database-per-tenant

No shared tables, no shared schema. Every tenant's records live in a physically separate database with its own credentials.

Per-tenant blob storage

Documents, images and DICOM studies are stored in tenant-scoped containers — access paths that never cross a tenant boundary.

Per-tenant encryption keys

Each tenant's data is encrypted under its own key. Compromise of one key exposes exactly one tenant — and revocation is surgical.

"A dropped WHERE clause can't cross tenants — there's no shared table to leak from."

Data Residency

Your data, where you need it.

BytePad deploys where your regulatory posture demands — same platform, same controls, in the boundary that fits your mission.

Azure Government

Dedicated US government cloud regions for federal, state and government-adjacent healthcare workloads.

US Gov boundary

AWS GovCloud

Isolated GovCloud (US) regions when your compliance program or agency partners standardize on AWS.

ITAR-ready regions

Commercial Cloud

Standard commercial regions for health systems and enterprises without a government boundary requirement.

Azure · AWS

Hybrid

Split deployments that keep specific data classes on-premises or in a designated boundary while the platform stays unified.

Phased migration

Transparency

Sub-processors, disclosed.

You should know exactly who touches your data, in what role, and under what controls — before you sign, not after.

The current sub-processor list is available on request.

We maintain a current register of every sub-processor — cloud infrastructure, AI services, and supporting tooling — with the role each plays and the controls each operates under. It ships alongside our security whitepaper, attestation reports and BAA templates through the documentation desk below, and customers are notified before any change.

Documentation Desk

Put us through your review.

Certification letters, SOC 2 report, security whitepaper, sub-processor list, BAA templates — request the package and we'll route it under NDA to your security team.

Prefer to talk? (703) 635-7676