Six security pillars cover every layer of the CareSphere platform — from edge IoT sensors to cloud databases.
Compliance
HIPAA and PHIPA regulatory frameworks, AWS BAA coverage, data retention policies, and breach notification procedures.
View compliance →Data Security
Column-level pgcrypto encryption for all 18 HIPAA identifiers, KMS-managed keys, schema isolation, and de-identified analytics exports.
View data security →Access Control
Role-based access control (RBAC), PostgreSQL Row Level Security, JWT authentication, Cognito SSO, and per-session audit trails.
View access control →Cloud Infrastructure
AWS-hosted on Aurora PostgreSQL with KMS-managed encryption, S3 Glacier archival, VPC isolation, and CloudWatch Logs SIEM integration.
View infrastructure →IoT & AI Edge Security
ESP32 sensors and on-premise AI brain nodes use mutual TLS, certificate-based auth, signed firmware, and local processing to minimise PHI exposure.
View IoT security →Responsible Disclosure
Found a vulnerability? We provide a clear disclosure process, acknowledge reports within 24 hours, and do not pursue legal action for good-faith research.
Report a vulnerability →Regulatory Alignment Status
Current alignment across regulatory frameworks
Security questions?
Our security team is available for compliance reviews, BAA requests, and penetration test reports.
security@spiritify.ai