Security and compliance

Protecting the data your residents trust you with

Security isn't a feature we bolted on, it's how the platform is built. PEOPLE - AI Workforce is HIPAA compliant: from authentication to audit trails, every layer is designed to keep PHI safe.

HIPAA compliant: and we sign your BAA

PEOPLE - AI Workforce operates as a HIPAA business associate: we sign a Business Associate Agreement with every community, PHI is encrypted in transit and at rest, and the platform runs on HIPAA-eligible cloud infrastructure. Resident data is used to do your community's work: never to train anyone else's models.

Defense in depth

Security at every layer

A consistent set of controls applied across the entire platform.

Authenticated access

JWT-based authentication with bcrypt-hashed credentials. Inactive accounts are blocked at login.

Role-based access control

Granular roles (Super Admin, Staff) scope every screen and API to exactly what a user should see.

Per-tenant data isolation

Each organization only ever sees its own communities and residents, enforced at the application layer.

Compliant e-signatures

ESIGN/UETA-aligned document signing with SHA-256 hashing, signature certificates and audit logging.

Audit trails

Signed clinical notes are immutable; edits and re-signs are recorded with a full audit history.

Hardened by default

Rate limiting, request timeouts and secure token handling protect every endpoint.

Secure file storage

Documents are stored in object storage and served through short-lived, presigned URLs.

Least-privilege everywhere

Server-controlled status and signature metadata, never trusted from the client.

Secure operations

Our commitments

Built for healthcare from the ground up

We make security decisions so your team can focus on care, without wondering whether a record is exposed or a document is shared too widely.

  • PHI protected with strict facility-level scoping
  • Encryption in transit (TLS) across the platform
  • Object storage access via short-lived presigned URLs
  • Server-side validation on every write

Before you sign anything

Ask for the paperwork, not a meeting

We do not hold a SOC 2 report or a HITRUST certification today, and we would rather say so than imply one. What we can put in your hands is what sits underneath one: the agreement we sign, the controls above written up for whoever reviews vendors for you, what happens to your records if you ever leave, and an operator running this in production who will take your call.

What you would be committing to

  • Priced per community. The security controls on this site are in every plan, never an add-on.
  • Start with what you need. Billing, therapy, payments and Medicaid switch on later with no migration, and your data and setup carry over.
  • An AI employee role is an optional add-on: add one any month, drop one any month.
  • Residents, financials, reports and documents export to CSV, Excel and PDF at any time, from inside the product. No lock-in, no exit fee.
What should we send?

A request for documents. Not a sales call.

Would rather see it running first? Book a demo.

The superagent

When the work goes through Aria

Aria is the interface to the system of record, and it has no data path of its own: every tool it calls is the code the screens call, with the caller's own request. So the controls above are the controls it runs under, and these are the ones it adds.

No identity of its own

There is no Aria account to escalate to. A question runs as the person who asked it, through the same organization and facility checks as the screens, so nothing typed into a conversation can grant access the asker does not already have.

Absent, not refused

What a person is not entitled to is filtered out before the model is told anything exists, so it cannot name it or mention that it is there. A record across an organization's line answers not-found, exactly as it does everywhere else.

Analysis that cannot become an export

Questions nobody built a screen for are answered with read-only SQL over purpose-built views, in a transaction that cannot write, under a role with no privilege anywhere else. Tenancy and entitlement are predicates inside the views, and clinical narrative is left out of them on purpose.

The button is the write

A change arrives as a card carrying its exact fields, one sentence saying how it is undone, and a signed single-use token that expires in two minutes. A person confirms, and the write runs outside the model's path. A change nobody can state a way back from is not offered at all, which is why medication administration and financial postings are not on this path.

Stamped as a person's work

Rows written this way record how they got there and are shown as their author's: drafted by Aria, confirmed by the person who pressed the button. The audit entry cannot be skipped.

Memory you can read and delete

What Aria remembers is held per person and never shared, shown line by line with the conversation each came from, and deletable one at a time. Conversation threads are never mirrored to a memory vendor, because a thread holds resident names, medications and incident narrative.

Questions

Security FAQ

Care for your residents. We'll protect the data.

Book a demo and see a platform that takes security as seriously as you do: or ask for the BAA, the security overview and the exit terms first, above.