Security

Security is at our core.

Valere Health has received a SOC 2 Type II attestation from a certified auditor, covering security, availability and confidentiality. Valere operates within a HIPAA-compliant architecture. Data is encrypted at rest and encrypted in transit, and all services and data are hosted on Amazon Web Services in databases allocated in the United States.

SOC 2 Type II

Valere Health security at a glance

SOC 2 Type II

An independent attestation covering security, availability and confidentiality, for the period June 15, 2025 to February 28, 2026.

Hosted on AWS, in the United States

Production runs on Amazon Web Services. Every data store is allocated in the US.

Encrypted at rest and in transit

Data stores are encrypted at rest with managed keys. Every session over the internet runs on TLS.

MFA on production

The production environment and source control open only to authorized employees with a valid multifactor method.

Backed up every day

Production and customer data are snapshotted daily and retained for a minimum of seven days.

Penetration-tested every year

An independent third party tests the platform annually. Critical and high findings are tracked to resolution.

99.99% uptime commitment

The availability commitment the platform is designed, load-balanced and monitored against.

Examined every year

A third-party assessor examines the system of controls annually, and leadership reviews the results twice a year.

Tested for Security

The examination covered the Interoperability Platform, Segue and Flex Plus. Every criterion in all three trust services categories applied.

Security

Protecting the platform, the software and your data

Security commitments are documented in the Master Data Services Agreement and in the Privacy Notice on this site. They cover the Interoperability Platform, Segue, Flex Plus and the customer data moving through them.

Password protection, encryption, verification and network security, applied to the service, the Interoperability Platform, Segue, Flex Plus and customer data.

Valere deploys safeguards against destruction, loss or alteration across the service, the application platform and customer data.

Valere notifies customers in responding to any security breach, any potential or actual unauthorized access, and any destruction, loss or alteration of customer data.

Employees are held to integrity and ethical standards throughout employment, and held accountable for their internal control responsibilities.

Performed annually to identify and remediate risks to the platform, the software and the systems supporting them, to an acceptable level.

Control deficiencies are communicated to the parties responsible for taking corrective action.

Keeping the platform up, and your data recoverable

The availability commitment starts with a number, and rests on the backup, encryption and redundancy underneath it.

The uptime commitment for the Interoperability Platform, Segue and Flex Plus.

Data stores housing production and confidential data are backed up according to the defined backup requirements.

Data stores housing production and confidential data are encrypted at rest.

Redundant infrastructure and information systems are maintained and tested annually, so a disruption has less impact on your operation.

Following confidential information from arrival to disposal

Confidentiality commitments track the information itself: how it is classified when it arrives, who may reach it, how it is protected, how long it is kept, and how it is destroyed.

Confidential information is identified and classified as it arrives or is created, then maintained to documented data handling, retention and confidentiality requirements.

Access to confidential information is restricted to authorized personnel based on job responsibilities and the principle of least privilege.

Confidential information is protected from unauthorized disclosure by access controls, encryption and system monitoring.

Confidential information is retained only for defined retention periods, established against contractual, business and regulatory requirements.

Policies and procedures govern destruction, deletion or anonymization when a retention period expires, or when a customer contract or service ends.

Employees and contractors adhere to confidentiality obligations and are held accountable for protecting confidential information throughout their engagement.

How the platform is protected

Thirty-five controls the attestation tested. Hover a card, or tap it on a phone, to see what it covers.

Executive oversight

The Executive Leadership Team owns security governance and meets twice a year to exercise it.

Policies reviewed every year

Every policy has an owner who reviews and approves it at least annually.

Training on hire and every year

Security awareness training is required when someone joins and annually after that.

Confidentiality from day one

Every employee signs a confidentiality agreement and acknowledges the Code of Ethics and Business Conduct on hire.

Background checks

Performed on candidates as part of hiring.

A sanctions policy

Documented disciplinary steps, up to termination, for failing to follow policy.

Centrally managed identity

Access to the production environment is managed through AWS Identity and Access Management.

MFA for every remote session

Production and source control open only to authorized employees with a valid multifactor method.

Password standards enforced

Passwords to the production environment and to version control are configured to the Password Management Policy.

Approved before provisioned

Access is granted after management authorization, revoked at termination through a standard form, and reviewed at least annually.

Least privilege

Administrative privileges are restricted to the people whose role requires them.

Segmented network

VPCs, security groups and subnets limit production access to authorized sources.

Web application firewall

A cloud-native WAF filters and blocks unauthorized traffic to the application.

Intrusion detection

A cloud-native IDS watches the network for known threats and suspicious activity.

Encrypted at rest

Every data store holding production or customer data is encrypted, with keys in a managed key service.

Encrypted in transit

Web application sessions run on TLS.

Stays in the United States

All data is held in AWS databases allocated in the US.

Snapshotted daily

Automated backups of production and customer data, retained for a minimum of seven days.

Classified on arrival

Data classification tiers, named owners and approved storage locations for confidential data.

Disposed of securely

Confidential data is destroyed, sanitized or rendered non-retrievable when no longer required.

A full asset inventory

An inventory in the cloud production console identifies, inventories and classifies every IT asset.

Continuous threat monitoring

Cloud-native threat detection and logging watch for anomalies across the production environment.

Continuous vulnerability scanning

Servers, containers and functions are scanned for vulnerabilities and network exposure; findings are tracked to resolution.

Annual penetration test

An independent third party tests the platform every year.

Anti-malware

Antivirus software scans the production environment and keeps its signatures current.

Peer-approved changes

Every change is tested, reviewed and approved by someone other than its author, and pull requests need a second approval before merging.

Segregated environments

Production is logically separated from development and testing.

Built to stay up

Load balancers spread traffic across availability zones and the container service autoscales on demand.

Tested recovery

Business continuity and incident response procedures are documented and tested every year.

Annual risk assessment

Likelihood times impact, scored and registered, including fraud and business-disruption risk.

A living control register

Controls and mitigations are documented and tracked in the risk management application.

Vendors reviewed every year

Each vendor's compliance report, or a security questionnaire, is obtained and evaluated annually.

Cloud providers reviewed too

AWS and Confluent Cloud compliance reports are downloaded and inspected every year.

Business impact assessed

An annual assessment identifies the risks in the technologies the business depends on.

Examined independently

A third-party assessor examines the system of controls every year.

Built for healthcare data

The platform moves patient health record data between the systems a post-acute operation runs. That shapes every control above.

A HIPAA-compliant architecture

Valere operates within a HIPAA-compliant architecture.

Patient data, shared on purpose

Patient health record data is streamed from healthcare systems, standardized, and made available only to authorized systems and users.

Access by job function

User and account data is restricted to employees based on job function, with ongoing monitoring.

You hear about it first

Valere commits to notifying customers of any breach or any potential or actual unauthorized access.

Questions security reviewers ask

On Amazon Web Services, in databases allocated in the United States. Valere Health does not run its own data centers; AWS and Confluent Cloud provide the hosting and managed event streaming, and their physical and environmental controls are reviewed every year through their own compliance reports.

Yes. Every data store holding production or customer data is encrypted at rest, and web application sessions run on TLS. Encryption keys live in a managed key service.

Only authorized employees, with a valid multifactor method, through centrally managed identity and access. Administrative privileges are restricted to the roles that need them, access is approved before it is granted, revoked at termination, and reviewed at least annually.

Through a documented change process. Every change is tested, reviewed and approved by someone other than its author; pull requests need a second approval before they merge; and production is logically separated from development and testing.

A documented incident management policy governs event handling. Incidents are tracked centrally to resolution, a post-incident analysis identifies the root cause, and the process is tested every year. No significant incidents were identified during the most recent attestation period.

Continuously by cloud-native monitoring and scanning, annually by an independent penetration test and a formal risk assessment, and annually by a third-party assessor who examines the whole system of controls. Leadership reviews the results twice a year.

Yes. The report is restricted to customers, prospective customers and their advisors, so it is shared on request rather than posted. Write to security@valere-health.com and we will send it under the usual terms.

Have concerns or questions about our security?

Ask a question, request the report, or report a potential security issue. It goes straight to the people responsible.