Security & Compliance

Compliance Is the Foundation

Patient data protection drives every architectural decision at GlucoWorks.

Security Controls

Defense in Depth

GlucoWorks executes a Business Associate Agreement with every customer before any PHI is processed. All data is encrypted, access is role-controlled, and every access event is logged.

Encryption

TLS 1.3 in transit. AES-256 at rest. KMS-managed keys in production.

Authentication & Access

MFA (TOTP), role-based access control, session timeout, account lockout.

Audit Logging

Every PHI access logged with user, IP, resource, timestamp. Immutable 7-year retention.

Data Integrity

Soft deletes with audit trails. Note versioning. Foreign key constraints.

Session Security

15-min timeout in production. Session regeneration on login. Max 3 concurrent sessions.

Security Monitoring

Automated detection of suspicious access patterns. Real-time alerting for critical events.

HIPAA Compliance

Security You Can Trust

All GlucoWorks products that handle PHI are deployed on Google Cloud Platform under a single Business Associate Agreement.

ServicePurposeCoverage
Google Cloud RunApplication hosting (compute)Google Cloud BAA
Cloud SQL (PostgreSQL)Patient records, clinical notes, audit logsBAA + AES-256 at rest
Cloud StoragePDF document storageBAA + encryption at rest
Secret ManagerAPI keys, credentialsBAA + KMS-backed
Vertex AI (Gemini)Vision-based PDF extractionGoogle Cloud BAA
Cloud Audit LogsImmutable compliance audit trailBAA + 7-year retention

Business Associate Agreements

GlucoWorks LLC executes BAAs with covered entity customers before any PHI is processed. Our standard BAA template is available upon request.

Request BAA Template

Compliance Roadmap

  • HIPAA — Active. BAA-covered GCP infrastructure
  • SOC 2 Type II — Planned for enterprise readiness
  • HITRUST — Evaluating for healthcare assurance
  • FDA SaMD — Separate regulatory track for future CDS products

Report a Security Concern

If you discover a security vulnerability in any GlucoWorks product, please contact our security team immediately.

security@gluco-works.com