TRUST CENTER
Security, privacy, and compliance are at the core of everything we build. Explore our framework for protecting your data and ensuring industry-leading standards.
HIPAA Compliant
Healthcare data protection standards
GDPR Compliant
EU data protection regulations
ISO/IEC 27001:2022
Information security management
Compliance
Independently verified against the frameworks that matter most for healthcare and enterprise data.
HIPAA
Health Insurance Portability and Accountability Act
- Protected Health Information (PHI) handling procedures
- Business Associate Agreements (BAA) available
- Encryption and access controls for healthcare data
- Audit logs for all data access
GDPR
General Data Protection Regulation (EU)
- Data Processing Agreements (DPA) with SCCs
- Data subject rights procedures documented
- Privacy by design principles implemented
- Sub-processor transparency maintained
PIPEDA
Personal Information Protection and Electronic Documents Act (Canada)
- Consent-based data collection
- Individual access to personal information
- Safeguards for personal information
- Accountability for data protection
HITRUST CSF
Common Security Framework for Healthcare
- Comprehensive security framework certification
- Annual assessment and validation
- Covers HIPAA, NIST, and ISO controls
- Third-party validated security posture
Security Controls
ISO/IEC 27001:2022 certified controls, continuously monitored across every operational area.
Information security for use of cloud services
Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization's information security requirements.
Authentication information
Allocation and management of authentication information shall be controlled by a management process, including advising personnel on the appropriate handling of authentication information.
Remote working
Security measures shall be implemented when personnel are working remotely to protect information accessed, processed or stored outside the organization's premises.
Application security requirements
Information security requirements shall be identified, specified and approved when developing or acquiring applications.
Clock synchronization
The clocks of information processing systems used by the organization shall be synchronized to approved time sources.
Infrastructure
Enterprise-grade redundancy built for continuous availability.
Subprocessors
Third-party services that process data on our behalf, each bound by a signed data processing agreement.
Amazon Web Services (AWS)
Cloud infrastructure and hosting
United States
Google Cloud Platform
Cloud services and AI infrastructure
United States
Anthropic
AI and machine learning services
United States
OpenAI
AI and language model services
United States
MongoDB
Database services and hosting
United States
Discord
Communication and collaboration
United States
Twilio
Communication APIs and messaging
United States
Stripe
Payment processing
United States
Escrow
Secure payment and fund management
United States
Policies
Our signed security and data-handling policies, available to download.
Access & Authentication
Data Protection
FAQ
Common questions about our security and compliance practices.
Data Storage, Transmission and Access Controls
Is my data stored and transmitted securely in Woltrio?
Your data is encrypted both in transit (between the browser and our servers) and at rest (when stored on our servers). We use AES-256 bit encryption while transferring your data to/from our servers and for storing data on our servers. AES-256 is the industry standard for storing and transferring sensitive data. All backups of your data are also encrypted using AES-256 bit encryption. We use TLS 1.3 to encrypt your data both between your browser and our servers and between our servers and other internal networks.
Is any of my data stored or processed using cloud-based services?
Yes, we use Amazon Web Services (AWS), Google Cloud Platform, and other industry-leading cloud providers to store and process your data in the cloud.
What third-party service providers does Woltrio use to store my data?
We use Amazon Web Services (AWS) and Google Cloud Platform as our primary cloud infrastructure providers. Our core infrastructure is hosted using these services. We have Business Associate Agreements (HIPAA BAA) and Data Processing Agreements which require these providers to meet the highest level of security and privacy for storing personal health information.
Do you have agreements with these third-party cloud providers?
Yes, we have HIPAA Business Associate Agreements and GDPR Data Processing Agreements with all vendors which store and process data on our behalf. These agreements ensure compliance with all applicable regulations.
How is my data protected from unauthorized access?
We have multi-factor authentication, role-based access controls (RBAC), IP whitelisting, and least privilege principles in place to restrict unauthorized access to data. Our cloud providers adhere to strict SOC 2 Type II auditing and reporting standards for managing access to data stored in their systems. All access is logged and monitored 24/7.
Do these cloud service providers have the ability to permanently delete my data?
Yes, these providers are mandated to provide options (which we utilize) to completely wipe data from their servers. We ensure complete data deletion upon request in compliance with GDPR and other privacy regulations.
What happens to my data in the event of a natural disaster?
Data is replicated across multiple redundant servers in different geographic regions within our environment, which mitigates the risk of loss of connectivity or data loss. We maintain multi-region redundancy with automated failover capabilities to ensure business continuity.
How will I be notified of changes in third-party providers who will have access to my data?
Third-party services are outlined in our Privacy Policy and Trust Center. Updates to this list of providers are communicated via our Privacy Policy updates and through the Subprocessors section of our Trust Center.
What happens when I delete my data from Woltrio?
When you request deletion of your data, we will erase it from our primary databases immediately. Data will remain in encrypted backups for up to 30 days as part of our disaster recovery procedures. We have automated batch processes to purge backups within a rolling 30-day cycle. After 30 days, your data is permanently and irreversibly deleted from all systems.
Data Exports
Can I export my data from Woltrio?
Yes, you can export your data at any time. We provide data portability in compliance with GDPR and other privacy regulations. Your export will be provided in standard formats (JSON, CSV, or PDF) that include all data associated with your account. Contact our support team to request a data export.
Can I request a record of all accesses and transfers of my data?
Yes, we can provide a comprehensive audit log of all access and transfer of your data upon request. We maintain detailed logs of all data access for security and compliance purposes. In general, we will only access your data at your request to assist with troubleshooting issues related to your use of our services.
Compliance
Is Woltrio GDPR compliant?
Yes, Woltrio is fully GDPR compliant. A signed Data Processing Agreement (DPA) with Standard Contractual Clauses (SCCs) is available upon request. We implement privacy by design principles, maintain data subject rights procedures, and ensure sub-processor transparency. Contact legal@woltrio.com for our DPA or if you have specific concerns about GDPR compliance.
Is Woltrio HIPAA compliant?
Yes, Woltrio is fully HIPAA compliant. We implement all required technical, physical, and administrative safeguards to protect Protected Health Information (PHI). A HIPAA Business Associate Agreement (BAA) is available for all healthcare clients. Contact legal@woltrio.com to request a BAA.
Is Woltrio HITRUST certified?
Yes, Woltrio is HITRUST CSF certified. This certification demonstrates our commitment to comprehensive information security and validates our security controls against HIPAA, NIST, and ISO standards through annual third-party assessments.
Is Woltrio ISO 27001 certified?
Yes, Woltrio is ISO 27001:2022 certified. This certification demonstrates our commitment to information security management and is validated through annual third-party audits. Our security controls cover organizational, people, and technological aspects of information security.
Is Woltrio PCI compliant?
Yes, payments processed through Woltrio are done in a PCI DSS compliant manner. We process payments via Stripe, which is a PCI Level 1 Service Provider. Your customers' credit card data is never stored on Woltrio's servers and is handled entirely by our PCI-compliant payment processor.
Can I get a Business Associate Agreement (BAA)?
Yes, a HIPAA Business Associate Agreement (BAA) is available upon request for all healthcare clients. Contact legal@woltrio.com if you need a BAA or have specific concerns about regulations outlined by your governing body.
What certifications and compliance standards does Woltrio maintain?
Woltrio maintains HIPAA compliance, GDPR compliance, HITRUST CSF certification, and ISO 27001:2022 certification. We also work with PCI-compliant payment processors and maintain SOC 2 Type II compliance (in progress). All certifications are validated through regular third-party audits.
AI and Data Usage
Is my data used to train AI models?
No, your data is never used to train AI models. The data we store and process is strictly used for providing our services to you. We do not sell, share, or use your data for any purpose other than delivering the services you've contracted for. When we use AI services from providers like OpenAI or Anthropic, we use enterprise agreements that explicitly prohibit the use of your data for model training.
What AI services does Woltrio use?
We use AI services from OpenAI and Anthropic for specific features like code generation, content assistance, and automation. All AI processing is done through enterprise agreements with strict data protection clauses. Your data is processed securely and is never retained by AI providers or used for training purposes.
How is my data protected when using AI features?
When AI features are used, your data is encrypted in transit using TLS 1.3, processed through enterprise API agreements with zero data retention policies, and never used for model training. We only send the minimum necessary data to AI services, and all processing complies with GDPR, HIPAA, and other applicable regulations.
Security and Incident Response
How does Woltrio handle security incidents?
We have a comprehensive incident response plan that includes immediate containment, investigation, and notification procedures. In the event of a security incident affecting personal data, we will notify affected parties within 48-72 hours as required by applicable regulations (GDPR, HIPAA, etc.). Our security team monitors systems 24/7 for potential threats.
How can I report a security concern?
Please report any security concerns immediately to security@woltrio.com. We take all security reports seriously and will respond within 24 hours. For urgent security issues, you can also contact our support team directly.
How often are security audits performed?
We conduct internal security audits quarterly and undergo annual third-party audits for our compliance certifications (HITRUST, ISO 27001). Our security controls are continuously monitored and tested. Penetration testing is performed at least annually by independent security firms.
What is Woltrio's uptime guarantee?
We maintain a 99.99% uptime SLA with enterprise-grade reliability and redundancy. Our infrastructure is distributed across multiple regions with automated failover capabilities. We have a Recovery Time Objective (RTO) of 4 hours and Recovery Point Objective (RPO) of 1 hour.
Still have questions? Our team is here to help at security@woltrio.com
Questions about our security.
Our security team is here to help with audits, agreements, and anything else you need to move forward with confidence.



