SECURITY

Security First. Always.

Your facility data is sensitive. Our security architecture is built to protect it at every layer, from infrastructure to application to AI processing.

Healthcare facility data demands the highest level of protection. Our security architecture is designed to meet the expectations of enterprise healthcare operators, REITs, and regulatory bodies.

Encrypted at Rest

AES-256 encryption for all stored data, including facility documents, reports, and user information.

Encrypted in Transit

TLS 1.3 for all data transmission. No unencrypted connections accepted.

Access Controls

Role-based access with principle of least privilege. Multi-factor authentication required.

INFRASTRUCTURE

Platform Security Architecture

Cloud Infrastructure

Hosted on SOC 2 certified cloud infrastructure with geographic redundancy. All servers located in U.S. data centers. No facility data leaves U.S. jurisdiction.

Network Security

Web application firewall (WAF), DDoS protection, intrusion detection systems, and network segmentation. All internal services communicate over encrypted channels.

Data Isolation

Each client's facility data is logically isolated. No cross-client data access is possible at the application or database level. Tenant isolation is enforced at multiple layers.

Backup and Recovery

Automated daily backups with point-in-time recovery. Backups encrypted and stored in geographically separate locations. Recovery time objective (RTO) under 4 hours.

APPLICATION

Application Security Controls

AUTHENTICATION

Multi-factor authentication (MFA) required for all accounts. Support for SSO/SAML integration for enterprise clients. Session management with automatic timeout.

AUTHORIZATION

Role-based access control (RBAC) with granular permissions. Facility-level access restrictions. Administrative actions require elevated privileges and are fully audited.

AUDIT LOGGING

Comprehensive audit trail for all data access, modifications, and administrative actions. Logs retained for minimum 12 months. Tamper-evident log storage.

VULNERABILITY MGMT

Regular penetration testing by third-party security firms. Automated dependency scanning. Responsible disclosure program. Critical vulnerabilities patched within 24 hours.

SECURE DEVELOPMENT

Secure SDLC practices including code review, static analysis, and security testing integrated into CI/CD pipeline. All code changes require peer review.

AI SECURITY

AI and Data Processing Security

Data Isolation in AI Processing

Your facility data is never used to train models that serve other clients. AI processing occurs in isolated environments with no cross-tenant data leakage. Model outputs are generated fresh for each assessment.

Regulatory Knowledge Base

Our regulatory intelligence is built from publicly available codes, standards, and CMS guidance documents. The Regulatory Brain's knowledge base is separate from client facility data and contains no proprietary client information.

Human Oversight

All AI-generated assessments are validated by licensed professionals with regulatory survey experience before delivery. Our system augments human expertise rather than replacing it.

COMPLIANCE

Compliance Framework

SOC 2

Type II

In Progress

HIPAA

Compliant

BAA Available

CCPA

Compliant

Privacy Rights Supported

Incident Response

We maintain a documented incident response plan with defined escalation procedures. In the event of a security incident affecting your data:

1

Detection and containment within 1 hour

2

Client notification within 24 hours

3

Root cause analysis within 72 hours

4

Full remediation report within 7 days

Security Questions?

Our team is available to discuss security requirements, provide documentation, or address specific concerns for your organization.

Contact Security Team

security@sourcepathsystems.com

Ready to see what a surveyor would find?

Join the Founders Cohort. 25 spots. $3,450 locked for life. September 30 deadline.