Trust & Security

Security and compliance at Alluxi

Alluxi is HIPAA compliant. We build software that handles protected health information, and we run our own company on the same standard we build to for our healthcare clients.

HIPAA compliant
A company-wide compliance program covering the HIPAA Privacy, Security, and Breach Notification Rules.
Risk analysis & attestation
We complete a formal security risk analysis and compliance attestation on a recurring cadence. Supporting documentation is available to prospective clients under NDA.
BAAs in place
We sign Business Associate Agreements with our healthcare clients and require them from any vendor that touches PHI.

Our compliance program

We maintain a documented security program with a designated security officer, written policies and procedures, and a recurring security risk analysis. Findings are tracked to remediation, and the program is reviewed as our tooling, team, and client work evolve.

Workforce training

Every team member completes HIPAA and security awareness training at onboarding and on a recurring basis. Access to client systems and PHI is limited to trained personnel with a need to know.

Business Associate Agreements

We execute a BAA with each healthcare client before any PHI flows through systems we build or operate, and we require BAAs from subcontractors and vendors that store or process PHI on our behalf.

Data protection

Data is encrypted in transit and at rest. Access follows least privilege, protected by multi-factor authentication, and is logged for audit. Production data stays in production — we do not use client PHI in development or test environments.

Secure development

Every change goes through code review before it ships. We keep development, staging, and production environments separated, manage dependencies for known vulnerabilities, and design audit trails and access controls into the systems we deliver.

Incident response

We maintain a documented incident response plan with defined roles and escalation paths, including breach notification procedures aligned with the HIPAA Breach Notification Rule and our contractual obligations to clients.

Doing vendor due diligence?

We're glad to support your security review. Request our compliance documentation, policy summaries, or a completed security questionnaire — available under NDA.

Contact us
alluxi logo

Get tips, case studies, and stay up to date on Alluxi.