HITRUST r2
The most rigorous certification in healthcare security — a validated assessment across the full control set, covering the platform and the operations behind it.
Trust Center
Healthcare data deserves defense-in-depth, not disclaimers. This page is how we run BytePad: a live security scorecard, independent certifications, per-tenant isolation by architecture, and the documentation your review team will ask for.
Scorecard measured continuously across the estate — not asserted annually.
Live Security Scorecard
Most trust pages show you last year's audit. Ours shows you today's posture: continuous control monitoring across every endpoint and environment, rolled into one score your security team can interrogate.
All controls passing across the estate — measured, not asserted.
Certifications & Frameworks
Third-party certifications and the control frameworks BytePad operations map to — with the posture stated honestly, badge by badge.
The most rigorous certification in healthcare security — a validated assessment across the full control set, covering the platform and the operations behind it.
Independent attestation that security, availability and confidentiality controls operate effectively over time — not just on audit day.
A certified information security management system — risk assessment, treatment and improvement run as a discipline, on the current 2022 revision.
Privacy, Security and Breach Notification rules built into how the platform handles PHI — with BAAs executed for every covered engagement.
Controls mapped to the NIST SP 800-53 catalog — the common language federal and government-adjacent security reviews expect.
Practices aligned to CMMC Level 2 for engagements that touch controlled unclassified information in the defense supply chain.
Deployments supporting the DoD Risk Management Framework authorization path — including Azure Government and AWS GovCloud hosting.
Certification letters, attestation reports and control mappings are available under NDA — request documentation.
Security Principles
Every control on this page traces back to one of four principles. They are how we make security decisions when the checklist runs out.
Every role, service and query gets the minimum access it needs — RBAC/ABAC enforced at the API seam, reviewed and re-certified on a schedule.
AES-256 at rest, TLS 1.2+ in transit, network isolation, and audit logging at every layer. No single control is ever the whole plan.
The same controls run in every environment — commercial, government or hybrid. There is no "lite" security tier and no unmanaged exception path.
Continuous control monitoring, a <24h mean time to patch, and recurring independent assessment — posture that gets stronger between audits, not staler.
Tenant Isolation
Many platforms separate tenants with a column and a WHERE clause. BytePad separates them with infrastructure: each tenant gets its own database, its own blob storage, and its own encryption key.
No shared tables, no shared schema. Every tenant's records live in a physically separate database with its own credentials.
Documents, images and DICOM studies are stored in tenant-scoped containers — access paths that never cross a tenant boundary.
Each tenant's data is encrypted under its own key. Compromise of one key exposes exactly one tenant — and revocation is surgical.
"A dropped WHERE clause can't cross tenants — there's no shared table to leak from."
Every tenant boundary is enforced by infrastructure — separate databases, separate storage, separate keys — before any application code runs.
Data Residency
BytePad deploys where your regulatory posture demands — same platform, same controls, in the boundary that fits your mission.
Dedicated US government cloud regions for federal, state and government-adjacent healthcare workloads.
US Gov boundaryIsolated GovCloud (US) regions when your compliance program or agency partners standardize on AWS.
ITAR-ready regionsStandard commercial regions for health systems and enterprises without a government boundary requirement.
Azure · AWSSplit deployments that keep specific data classes on-premises or in a designated boundary while the platform stays unified.
Phased migrationTransparency
You should know exactly who touches your data, in what role, and under what controls — before you sign, not after.
We maintain a current register of every sub-processor — cloud infrastructure, AI services, and supporting tooling — with the role each plays and the controls each operates under. It ships alongside our security whitepaper, attestation reports and BAA templates through the documentation desk below, and customers are notified before any change.
Documentation Desk
Certification letters, SOC 2 report, security whitepaper, sub-processor list, BAA templates — request the package and we'll route it under NDA to your security team.
Prefer to talk? (703) 635-7676