Security
We host our production infrastructure on Amazon Web Services (AWS) in the US East (N. Virginia – us-east-1) and US East (Ohio – us-east-2) Regions. These secure, world-class facilities deliver massive scale, geographic redundancy, and industry-leading physical and logical security. Our multi-region architecture provides high availability with extremely low latency between the two regions (typically 10-15 ms RTT), along with redundant power systems, advanced cooling, enterprise-grade networking, and continuous compliance validations. This modern cloud infrastructure significantly enhances our previous colocation environment with greater resilience, elasticity, and security controls.
Service Organization Control (SOC) 1, 2, & 3 Reports
Health Information Trust (HITRUST) Alliance Common Security Framework (CSF) Validation (for in-scope services)
Payment Card Industry Data Security Standard (PCI DSS) Attestation of Compliance (Level 1)
Support for EU-U.S. Data Privacy Framework and GDPR via AWS Data Processing Addendum
Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) Registration
Additional certifications including ISO 27001, ISO 27017, and ISO 27018
IT Compliance
Operations Support Center (OSC)
24x7x365 AWS global operations support with dedicated customer monitoring
Multi-factor authentication (MFA) and role-based Identity & Access Management (IAM)
Granular access controls, least-privilege policies, and continuous access review
Video surveillance, logging, and physical security managed by AWS at the facility level
Customer-managed logical security with lockable logical “cages” via VPC isolation, security groups, and network segmentation
Multi-Tiered Security System
Physical Layer (AWS-managed): Perimeter fencing, professional security staff, multi-factor building access, 24/7 CCTV, intrusion detection, and regular third-party audits.
Infrastructure Layer: Redundant power, cooling, fire suppression, and networking.
Logical Layer (Customer + AWS): AWS Nitro System security, encryption at rest and in transit (AWS KMS), VPC network isolation, Amazon GuardDuty threat detection, and AWS Security Hub.
Application & Data Layer: Customer-controlled encryption, access policies, monitoring, and compliance configurations.
Facility electrical, mechanical, and environmental systems monitored by AWS
Comprehensive monitoring of compute, storage, networking, and application components
Centralized logging and event aggregation via AWS CloudTrail, Amazon CloudWatch, and AWS Security Hub
Real-time threat detection, automated alerts, and proactive incident response capabilities