Security & trust
Enterprise-grade security. Honest about where we are.
Here is exactly what protects your data today and what is in audit. We do not claim a certification before it is earned.
HIPAA compliant · BAA ready · AES-256 and TLS 1.3 · FHIR-native
How your data is protected
Six pillars, built in from the start.
Encryption everywhere
AES-256-GCM at rest, TLS 1.3 in transit, with a dedicated key-management service.
Tenant isolation
Row-level security in PostgreSQL keeps every organization's data cleanly separated.
Access control
Fail-closed RBAC with SAML 2.0 and OIDC single sign-on for AD and Okta.
Audit & accountability
Every access is logged with user, timestamp, and reason. AI decisions carry explainability traces.
FHIR-native model
No proprietary schemas and no lock-in. Your data stays standards-based and portable.
Deployment flexibility
Cloud, private cloud, or on-premise, including air-gapped, for data-residency requirements.
Legal agreements
HIPAA Business Associate Agreement (BAA). Available for enterprise customers and signed before any protected health information flows.
GDPR Data Processing Agreement (DPA). Standard contractual clauses and a DPA are available for customers with EU data-processing needs.
Responsible disclosure
If you believe you have found a security vulnerability, we want to hear from you. Please email hello@agilimed.com with the details and we will respond promptly. We ask that you give us reasonable time to investigate and remediate before any public disclosure.
Questions about security?
Talk to our team.
We are happy to walk your security and compliance teams through the details.