Back to home

Security & compliance

How we protect patient data and earn trust

DEXYTECH builds medical software with the controls and practices aligned to HIPAA, SOC 2 and ISO 27001. This page describes our commitment; it is not a certification or legal guarantee. For specific contractual assurances, please contact us directly.

Frameworks we align with

HIPAA

Health Insurance Portability and Accountability Act

Safeguarding protected health information through administrative, physical and technical controls.

SOC 2

Service Organization Control 2

Trust services criteria covering security, availability, processing integrity, confidentiality and privacy.

ISO 27001

Information Security Management Standard

A structured approach to managing information security risks across people, processes and technology.

Our security practices

Security-first architecture

We start with least-privilege access, segmented environments and strong authentication. Production secrets are never stored in source code, and infrastructure changes are reviewed before they reach live systems.

Encryption and data protection

Data is encrypted in transit using TLS and at rest using provider-managed encryption. We classify data by sensitivity, apply retention limits, and support export and deletion workflows for patient and customer records.

Audit logging and monitoring

Critical actions — logins, record creation, configuration changes and exports — are logged with timestamps and actor identity. Logs are retained and reviewed to support incident response and compliance enquiries.

Privacy by design

We collect only what is necessary, separate identifiers where feasible, and build consent and access controls into the product. Privacy impact reviews are part of feature planning, not an afterthought.

Availability and resilience

Backups, redundancy planning and documented runbooks help keep clinical services running. We test recovery procedures and track dependencies so outages can be isolated and resolved quickly.

Continuous compliance review

Access lists, policies and dependencies are reviewed on a regular schedule. We track known vulnerabilities, patch promptly, and train the team on secure development practices.

Questions or audit requests?

If you are evaluating DEXYTECH for a healthcare deployment and need a security questionnaire, architecture review or compliance discussion, our team is happy to help.

Contact compliance team