Built for healthcare
privacy and security
CredVault protects credential data with encryption, access controls, audit logging, and enterprise-grade infrastructure.
Security posture
Every layer of CredVault is designed with defense in depth.
SOC 2 & Compliance
Our infrastructure is hosted on AWS (SOC 2 Type II, HIPAA-eligible). Credential data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
Encryption
All data in transit is protected by TLS 1.2+ with strong cipher suites. Data at rest is encrypted using AES-256. Access to sensitive provider identifiers, including SSN and date of birth, is restricted by role-based access controls and logged to an append-only audit trail.
Access Controls
Every API request is authenticated via JWT with per-user token versioning. Role-based access (member, owner, admin) controls what each user can view or modify. All access is logged to an append-only audit trail.
Audit Logging
All credential changes, provider modifications, and administrative actions are recorded with timestamp, user ID, action type, and resource identifier.
Infrastructure
Hosted on AWS EC2 in the US. Backend runs on isolated containers with health checks and automated restarts.
Data Deletion
Account deletion removes all provider and credential data. Exports are available on request before deletion.
HIPAA & Business Associate Agreements
Clear answers about compliance, BAAs, and data handling.
Does CredVault sign Business Associate Agreements?
How does CredVault approach HIPAA and healthcare privacy?
What data should we NOT upload?
Where is our data stored?
How long do you keep our data?
How do team permissions work?
Can we export our data before cancellation or deletion?
What happens if we cancel?
Subprocessors
Third-party subprocessors used to operate CredVault.
| Subprocessor | Purpose | Data location |
|---|---|---|
| AWS EC2 | Cloud infrastructure & hosting | United States |
| AWS S3 | Document/file storage | United States |
| Resend | Transactional email delivery | United States |
| Twilio | SMS notification delivery | United States |
| Stripe | Billing & payment processing | United States |
| AI Document Parsing | AI-powered data extraction from uploaded files | United States (cached) |
| JWT/Sessions | Authentication tokens — no third-party auth provider | N/A (self-managed) |
Have compliance questions?
We're happy to share security documentation, review vendor assessments, or start the BAA process.
Contact our security team