TRUST CENTER

Security, privacy, and compliance are at the core of everything we build. Explore our framework for protecting your data and ensuring industry-leading standards.

HIPAA Compliant

Healthcare data protection standards

GDPR Compliant

EU data protection regulations

ISO/IEC 27001:2022

Information security management

Compliance

Independently verified against the frameworks that matter most for healthcare and enterprise data.

HIPAA

Compliant

Health Insurance Portability and Accountability Act

  • Protected Health Information (PHI) handling procedures
  • Business Associate Agreements (BAA) available
  • Encryption and access controls for healthcare data
  • Audit logs for all data access

GDPR

Compliant

General Data Protection Regulation (EU)

  • Data Processing Agreements (DPA) with SCCs
  • Data subject rights procedures documented
  • Privacy by design principles implemented
  • Sub-processor transparency maintained

PIPEDA

Aligned

Personal Information Protection and Electronic Documents Act (Canada)

  • Consent-based data collection
  • Individual access to personal information
  • Safeguards for personal information
  • Accountability for data protection

HITRUST CSF

Certified

Common Security Framework for Healthcare

  • Comprehensive security framework certification
  • Annual assessment and validation
  • Covers HIPAA, NIST, and ISO controls
  • Third-party validated security posture

Security Controls

ISO/IEC 27001:2022 certified controls, continuously monitored across every operational area.

Information security for use of cloud services

Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization's information security requirements.

Authentication information

Allocation and management of authentication information shall be controlled by a management process, including advising personnel on the appropriate handling of authentication information.

Remote working

Security measures shall be implemented when personnel are working remotely to protect information accessed, processed or stored outside the organization's premises.

Application security requirements

Information security requirements shall be identified, specified and approved when developing or acquiring applications.

Clock synchronization

The clocks of information processing systems used by the organization shall be synchronized to approved time sources.

Infrastructure

Enterprise-grade redundancy built for continuous availability.

99.99%
Uptime SLA
Enterprise-grade reliability with redundancy
4 Hours
Recovery Time (RTO)
Maximum time to restore systems
1 Hour
Recovery Point (RPO)
Maximum data loss time window
Multi-Region
Data Centers
Geographic redundancy and failover

Subprocessors

Third-party services that process data on our behalf, each bound by a signed data processing agreement.

Amazon Web Services (AWS) logo

Amazon Web Services (AWS)

Cloud infrastructure and hosting

United States

Google Cloud Platform logo

Google Cloud Platform

Cloud services and AI infrastructure

United States

Anthropic logo

Anthropic

AI and machine learning services

United States

OpenAI logo

OpenAI

AI and language model services

United States

MongoDB logo

MongoDB

Database services and hosting

United States

Discord logo

Discord

Communication and collaboration

United States

Twilio logo

Twilio

Communication APIs and messaging

United States

Stripe logo

Stripe

Payment processing

United States

Escrow logo

Escrow

Secure payment and fund management

United States

FAQ

Common questions about our security and compliance practices.

Data Storage, Transmission and Access Controls

Is my data stored and transmitted securely in Woltrio?

Your data is encrypted both in transit (between the browser and our servers) and at rest (when stored on our servers). We use AES-256 bit encryption while transferring your data to/from our servers and for storing data on our servers. AES-256 is the industry standard for storing and transferring sensitive data. All backups of your data are also encrypted using AES-256 bit encryption. We use TLS 1.3 to encrypt your data both between your browser and our servers and between our servers and other internal networks.

Is any of my data stored or processed using cloud-based services?

Yes, we use Amazon Web Services (AWS), Google Cloud Platform, and other industry-leading cloud providers to store and process your data in the cloud.

What third-party service providers does Woltrio use to store my data?

We use Amazon Web Services (AWS) and Google Cloud Platform as our primary cloud infrastructure providers. Our core infrastructure is hosted using these services. We have Business Associate Agreements (HIPAA BAA) and Data Processing Agreements which require these providers to meet the highest level of security and privacy for storing personal health information.

Do you have agreements with these third-party cloud providers?

Yes, we have HIPAA Business Associate Agreements and GDPR Data Processing Agreements with all vendors which store and process data on our behalf. These agreements ensure compliance with all applicable regulations.

How is my data protected from unauthorized access?

We have multi-factor authentication, role-based access controls (RBAC), IP whitelisting, and least privilege principles in place to restrict unauthorized access to data. Our cloud providers adhere to strict SOC 2 Type II auditing and reporting standards for managing access to data stored in their systems. All access is logged and monitored 24/7.

Do these cloud service providers have the ability to permanently delete my data?

Yes, these providers are mandated to provide options (which we utilize) to completely wipe data from their servers. We ensure complete data deletion upon request in compliance with GDPR and other privacy regulations.

What happens to my data in the event of a natural disaster?

Data is replicated across multiple redundant servers in different geographic regions within our environment, which mitigates the risk of loss of connectivity or data loss. We maintain multi-region redundancy with automated failover capabilities to ensure business continuity.

How will I be notified of changes in third-party providers who will have access to my data?

Third-party services are outlined in our Privacy Policy and Trust Center. Updates to this list of providers are communicated via our Privacy Policy updates and through the Subprocessors section of our Trust Center.

What happens when I delete my data from Woltrio?

When you request deletion of your data, we will erase it from our primary databases immediately. Data will remain in encrypted backups for up to 30 days as part of our disaster recovery procedures. We have automated batch processes to purge backups within a rolling 30-day cycle. After 30 days, your data is permanently and irreversibly deleted from all systems.

Data Exports

Can I export my data from Woltrio?

Yes, you can export your data at any time. We provide data portability in compliance with GDPR and other privacy regulations. Your export will be provided in standard formats (JSON, CSV, or PDF) that include all data associated with your account. Contact our support team to request a data export.

Can I request a record of all accesses and transfers of my data?

Yes, we can provide a comprehensive audit log of all access and transfer of your data upon request. We maintain detailed logs of all data access for security and compliance purposes. In general, we will only access your data at your request to assist with troubleshooting issues related to your use of our services.

Compliance

Is Woltrio GDPR compliant?

Yes, Woltrio is fully GDPR compliant. A signed Data Processing Agreement (DPA) with Standard Contractual Clauses (SCCs) is available upon request. We implement privacy by design principles, maintain data subject rights procedures, and ensure sub-processor transparency. Contact legal@woltrio.com for our DPA or if you have specific concerns about GDPR compliance.

Is Woltrio HIPAA compliant?

Yes, Woltrio is fully HIPAA compliant. We implement all required technical, physical, and administrative safeguards to protect Protected Health Information (PHI). A HIPAA Business Associate Agreement (BAA) is available for all healthcare clients. Contact legal@woltrio.com to request a BAA.

Is Woltrio HITRUST certified?

Yes, Woltrio is HITRUST CSF certified. This certification demonstrates our commitment to comprehensive information security and validates our security controls against HIPAA, NIST, and ISO standards through annual third-party assessments.

Is Woltrio ISO 27001 certified?

Yes, Woltrio is ISO 27001:2022 certified. This certification demonstrates our commitment to information security management and is validated through annual third-party audits. Our security controls cover organizational, people, and technological aspects of information security.

Is Woltrio PCI compliant?

Yes, payments processed through Woltrio are done in a PCI DSS compliant manner. We process payments via Stripe, which is a PCI Level 1 Service Provider. Your customers' credit card data is never stored on Woltrio's servers and is handled entirely by our PCI-compliant payment processor.

Can I get a Business Associate Agreement (BAA)?

Yes, a HIPAA Business Associate Agreement (BAA) is available upon request for all healthcare clients. Contact legal@woltrio.com if you need a BAA or have specific concerns about regulations outlined by your governing body.

What certifications and compliance standards does Woltrio maintain?

Woltrio maintains HIPAA compliance, GDPR compliance, HITRUST CSF certification, and ISO 27001:2022 certification. We also work with PCI-compliant payment processors and maintain SOC 2 Type II compliance (in progress). All certifications are validated through regular third-party audits.

AI and Data Usage

Is my data used to train AI models?

No, your data is never used to train AI models. The data we store and process is strictly used for providing our services to you. We do not sell, share, or use your data for any purpose other than delivering the services you've contracted for. When we use AI services from providers like OpenAI or Anthropic, we use enterprise agreements that explicitly prohibit the use of your data for model training.

What AI services does Woltrio use?

We use AI services from OpenAI and Anthropic for specific features like code generation, content assistance, and automation. All AI processing is done through enterprise agreements with strict data protection clauses. Your data is processed securely and is never retained by AI providers or used for training purposes.

How is my data protected when using AI features?

When AI features are used, your data is encrypted in transit using TLS 1.3, processed through enterprise API agreements with zero data retention policies, and never used for model training. We only send the minimum necessary data to AI services, and all processing complies with GDPR, HIPAA, and other applicable regulations.

Security and Incident Response

How does Woltrio handle security incidents?

We have a comprehensive incident response plan that includes immediate containment, investigation, and notification procedures. In the event of a security incident affecting personal data, we will notify affected parties within 48-72 hours as required by applicable regulations (GDPR, HIPAA, etc.). Our security team monitors systems 24/7 for potential threats.

How can I report a security concern?

Please report any security concerns immediately to security@woltrio.com. We take all security reports seriously and will respond within 24 hours. For urgent security issues, you can also contact our support team directly.

How often are security audits performed?

We conduct internal security audits quarterly and undergo annual third-party audits for our compliance certifications (HITRUST, ISO 27001). Our security controls are continuously monitored and tested. Penetration testing is performed at least annually by independent security firms.

What is Woltrio's uptime guarantee?

We maintain a 99.99% uptime SLA with enterprise-grade reliability and redundancy. Our infrastructure is distributed across multiple regions with automated failover capabilities. We have a Recovery Time Objective (RTO) of 4 hours and Recovery Point Objective (RPO) of 1 hour.

Still have questions? Our team is here to help at security@woltrio.com

Questions about our security.

Our security team is here to help with audits, agreements, and anything else you need to move forward with confidence.

Powering Your Solutions With

Python
Selenium
React Native
HL7 FHIR
Flutter
TypeScript
Flutter
Python
Selenium
React Native
HL7 FHIR
TypeScript
Python
Selenium
React Native
HL7 FHIR
Flutter
TypeScript
Flutter
Python
Selenium
React Native
HL7 FHIR
TypeScript
Trust Center | Security & Compliance | Woltrio