Security and Compliance

Built for Secure Healthcare Automation

Decisive Connect is a cloud-native healthcare automation platform designed to handle sensitive healthcare workflows with strong access controls, encryption, tenant isolation, auditability, and secure software development practices.

SOC 2 Type IIHIPAAAWS-hosted SaaSTenant isolationRBACTLS 1.2+AES-256
SOC 2 badge powered by Vanta

SOC 2 Type II

Decisive Connect maintains SOC 2 Type II certification with annual external audit review and attestation. The latest SOC 2 Type II report may be reviewed under NDA.

HIPAA badge powered by Vanta

HIPAA

The platform is designed to support HIPAA-aligned handling of PHI. Customers can elect a HIPAA Business Associate Agreement when Decisive Connect handles PHI on behalf of a covered entity or business associate.

Security Program Governance

The security program is owned by the Chief Technology Officer, who reports quarterly to leadership. Policies and procedures are maintained in a centralized compliance management system, and staff must review training and acknowledge security policies annually.

Risk and Testing

The security program is aligned with the NIST Cybersecurity Framework, mapped to the SOC 2 Trust Services Criteria, and supported by continuous vulnerability scanning and annual third-party audits and oversight.

Platform Security Controls

Designed to Protect PHI, Workflows, and Client Data

Minimizing PHI Sprawl

Data-at-Source Architecture

Decisive Connect is designed to minimize unnecessary PHI replication wherever feasible. Whenever possible, integrations evaluate PHI where it already resides and avoid unnecessary copies within the platform. This reduces data sprawl and helps simplify access-control risk and mitigation.

  • Integration-first approach designed to use source-system data when feasible
  • Avoids redundant copies of PHI unless required by the client workflow
  • Supports clinical, administrative, and financial workflows without requiring broad data replication

Encryption In Transit and At Rest

PHI Handling and Encryption

The platform is designed to protect PHI from unauthorized access through encryption in transit and encryption at rest.

  • TLS 1.2 minimum, with TLS 1.3 used where available, for HTTPS API traffic, user access, and SFTP transfers
  • AES-256 minimum encryption for PHI stored at rest

Least-Privilege Access

Role-Based Access Control

Role-based access control restricts access to authorized users and systems based on assigned roles and permissions. Client administrators can define roles, permissions, and system-user access for integrations.

  • Client-defined roles and permissions for platform users
  • System API integrations use associated system users so access can be controlled for external systems
  • User and system account role maintenance is managed in the platform
  • Analytics components can be isolated to specific user groups for more granular dashboard and drill-down access

Visibility Into Sensitive Data Access

Auditability and Analytics Access Review

Because analytics drill-down views can expose sensitive data, Decisive Connect includes additional analytics permissions and auditability features to help administrators review access to dashboards and views.

  • Granular analytics user-group permissions
  • Administrative dashboards and reports for analytics access review
  • Audit visibility for instances of users accessing analytics dashboards and views

Secure Cloud Deployment

Hosting and Network Security

Decisive Connect is hosted on Amazon Web Services and uses containerized deployments with Docker and Kubernetes. Tenant isolation is enforced through platform, application, and data-access controls designed to keep each client's users, workflows, and data logically separated.

  • AWS-hosted SaaS offering in U.S.-based regions
  • Tenant-aware access controls and data-access boundaries
  • Private network segmentation limits direct public exposure of internal services
  • Web application firewall protections, managed rule sets, and reputation-based filtering
  • DDoS mitigation controls help protect internet-facing services
  • Threat detection, centralized secret management, and network-scoped controls support defense in depth

Secure API and Key Management

Integration and Secrets Security

The platform restricts embedded access tokens and API keys in code. Security keys and access tokens are externalized from the application code and housed in centralized key management using AWS Secrets Manager.

  • API data transmissions use HTTPS with TLS 1.2 minimum
  • Batch file transfers use SFTP
  • Security keys and access tokens are excluded from source control
  • Centralized secret storage helps mitigate secrets-sprawl risk

Security in the Release Process

Secure Software Development

Secure software development practices are integrated into development and release cycles. Releases are scanned, reviewed, and blocked when security testing identifies unresolved issues.

  • Every release image is put through stringent vulnerability scanning
  • Medium and high severity vulnerabilities must be resolved before client release
  • Automated security testing is incorporated into daily development and release cycles
  • Security test failures prevent release promotion until resolved
  • High-risk items require security design review and security testing before production release

Availability, Retention, and Recovery

Business Continuity and Disaster Recovery

The Decisive Connect data layer is designed with availability, backup, and disaster-recovery mechanisms intended to reduce outage risk, limit data loss, and support timely recovery.

  • Database replication and standby capacity support resilience for critical data services
  • Failover processes are designed to support recovery from primary database failure scenarios
  • Disaster-recovery testing is incorporated into release and operational validation
  • Encrypted backups are maintained according to defined retention policies
  • Customer data retention and export requirements can be configured based on contractual and workflow needs
  • Contract termination processes support customer data export and controlled data removal

Security Review and Compliance Requests

Security officers, compliance teams, IT administrators, and prospective customers may request additional security documentation, including SOC 2 materials under NDA, by contacting Decisive Connect.