Data privacy is our priority. We implement a redundant and secure architecture to protect critical clinical information.
We follow digital health industry best practices:
Compliance with the Federal Law on Protection of Personal Data Held by Private Parties.
We adopt standard industry guidelines for health data security and privacy.
We apply international principles such as the right to be forgotten and data minimization.
Our internal processes follow controls based on security management standards.
We design our technology with redundancy and data protection at its core.
We align with LFPDPPP (Mexico) for the responsible, ethical, and legal handling of sensitive personal data.
Our infrastructure operates redundantly across AWS and GCP, ensuring high availability and resilience against failures.
We maintain detailed records (logs) of access and modifications to ensure data integrity and traceability.
Advanced technical and organizational measures protecting your information every day.
Your information travels securely via standard protocols (TLS/SSL) and is encrypted at rest.
We generate unalterable, geographically distributed backups (Multi-Cloud) for disaster recovery.
Role-Based Access Control (RBAC) to ensure only authorized personnel access data.
We apply software engineering best practices to minimize risks in our code.
All staff are certified by the CITI Program in 'Data or Specimens Only Research' for ethical data handling.
We maintain a Disaster Recovery Plan (DRP) and a Business Continuity Plan (BCP), with annual recovery drills and impact analysis.
A formal incident response plan with defined roles, and a post-incident review process to continuously strengthen our controls.
Every critical vendor signs a Data Processing Agreement (DPA) and, where applicable, a HIPAA Business Associate Agreement (BAA), with annual review of their security certifications.