Security is at our core.
Valere Health has received a SOC 2 Type II attestation from a certified auditor, covering security, availability and confidentiality. Valere operates within a HIPAA-compliant architecture. Data is encrypted at rest and encrypted in transit, and all services and data are hosted on Amazon Web Services in databases allocated in the United States.
Valere Health security at a glance
SOC 2 Type II
An independent attestation covering security, availability and confidentiality, for the period June 15, 2025 to February 28, 2026.
Hosted on AWS, in the United States
Production runs on Amazon Web Services. Every data store is allocated in the US.
Encrypted at rest and in transit
Data stores are encrypted at rest with managed keys. Every session over the internet runs on TLS.
MFA on production
The production environment and source control open only to authorized employees with a valid multifactor method.
Backed up every day
Production and customer data are snapshotted daily and retained for a minimum of seven days.
Penetration-tested every year
An independent third party tests the platform annually. Critical and high findings are tracked to resolution.
99.99% uptime commitment
The availability commitment the platform is designed, load-balanced and monitored against.
Examined every year
A third-party assessor examines the system of controls annually, and leadership reviews the results twice a year.
Tested for Security
The examination covered the Interoperability Platform, Segue and Flex Plus. Every criterion in all three trust services categories applied.
Security
Protecting the platform, the software and your data
Security commitments are documented in the Master Data Services Agreement and in the Privacy Notice on this site. They cover the Interoperability Platform, Segue, Flex Plus and the customer data moving through them.
Password protection, encryption, verification and network security, applied to the service, the Interoperability Platform, Segue, Flex Plus and customer data.
Valere deploys safeguards against destruction, loss or alteration across the service, the application platform and customer data.
Valere notifies customers in responding to any security breach, any potential or actual unauthorized access, and any destruction, loss or alteration of customer data.
Employees are held to integrity and ethical standards throughout employment, and held accountable for their internal control responsibilities.
Performed annually to identify and remediate risks to the platform, the software and the systems supporting them, to an acceptable level.
Control deficiencies are communicated to the parties responsible for taking corrective action.
Keeping the platform up, and your data recoverable
The availability commitment starts with a number, and rests on the backup, encryption and redundancy underneath it.
The uptime commitment for the Interoperability Platform, Segue and Flex Plus.
Data stores housing production and confidential data are backed up according to the defined backup requirements.
Data stores housing production and confidential data are encrypted at rest.
Redundant infrastructure and information systems are maintained and tested annually, so a disruption has less impact on your operation.
Following confidential information from arrival to disposal
Confidentiality commitments track the information itself: how it is classified when it arrives, who may reach it, how it is protected, how long it is kept, and how it is destroyed.
Confidential information is identified and classified as it arrives or is created, then maintained to documented data handling, retention and confidentiality requirements.
Access to confidential information is restricted to authorized personnel based on job responsibilities and the principle of least privilege.
Confidential information is protected from unauthorized disclosure by access controls, encryption and system monitoring.
Confidential information is retained only for defined retention periods, established against contractual, business and regulatory requirements.
Policies and procedures govern destruction, deletion or anonymization when a retention period expires, or when a customer contract or service ends.
Employees and contractors adhere to confidentiality obligations and are held accountable for protecting confidential information throughout their engagement.
How the platform is protected
Thirty-five controls the attestation tested. Hover a card, or tap it on a phone, to see what it covers.
The Executive Leadership Team owns security governance and meets twice a year to exercise it.
Every policy has an owner who reviews and approves it at least annually.
Security awareness training is required when someone joins and annually after that.
Every employee signs a confidentiality agreement and acknowledges the Code of Ethics and Business Conduct on hire.
Performed on candidates as part of hiring.
Documented disciplinary steps, up to termination, for failing to follow policy.
Access to the production environment is managed through AWS Identity and Access Management.
Production and source control open only to authorized employees with a valid multifactor method.
Passwords to the production environment and to version control are configured to the Password Management Policy.
Access is granted after management authorization, revoked at termination through a standard form, and reviewed at least annually.
Administrative privileges are restricted to the people whose role requires them.
VPCs, security groups and subnets limit production access to authorized sources.
A cloud-native WAF filters and blocks unauthorized traffic to the application.
A cloud-native IDS watches the network for known threats and suspicious activity.
Every data store holding production or customer data is encrypted, with keys in a managed key service.
Web application sessions run on TLS.
All data is held in AWS databases allocated in the US.
Automated backups of production and customer data, retained for a minimum of seven days.
Data classification tiers, named owners and approved storage locations for confidential data.
Confidential data is destroyed, sanitized or rendered non-retrievable when no longer required.
An inventory in the cloud production console identifies, inventories and classifies every IT asset.
Cloud-native threat detection and logging watch for anomalies across the production environment.
Servers, containers and functions are scanned for vulnerabilities and network exposure; findings are tracked to resolution.
An independent third party tests the platform every year.
Antivirus software scans the production environment and keeps its signatures current.
Every change is tested, reviewed and approved by someone other than its author, and pull requests need a second approval before merging.
Production is logically separated from development and testing.
Load balancers spread traffic across availability zones and the container service autoscales on demand.
Business continuity and incident response procedures are documented and tested every year.
Likelihood times impact, scored and registered, including fraud and business-disruption risk.
Controls and mitigations are documented and tracked in the risk management application.
Each vendor's compliance report, or a security questionnaire, is obtained and evaluated annually.
AWS and Confluent Cloud compliance reports are downloaded and inspected every year.
An annual assessment identifies the risks in the technologies the business depends on.
A third-party assessor examines the system of controls every year.
Built for healthcare data
The platform moves patient health record data between the systems a post-acute operation runs. That shapes every control above.
A HIPAA-compliant architecture
Valere operates within a HIPAA-compliant architecture.
Patient data, shared on purpose
Patient health record data is streamed from healthcare systems, standardized, and made available only to authorized systems and users.
Access by job function
User and account data is restricted to employees based on job function, with ongoing monitoring.
You hear about it first
Valere commits to notifying customers of any breach or any potential or actual unauthorized access.
Questions security reviewers ask
On Amazon Web Services, in databases allocated in the United States. Valere Health does not run its own data centers; AWS and Confluent Cloud provide the hosting and managed event streaming, and their physical and environmental controls are reviewed every year through their own compliance reports.
Yes. Every data store holding production or customer data is encrypted at rest, and web application sessions run on TLS. Encryption keys live in a managed key service.
Only authorized employees, with a valid multifactor method, through centrally managed identity and access. Administrative privileges are restricted to the roles that need them, access is approved before it is granted, revoked at termination, and reviewed at least annually.
Through a documented change process. Every change is tested, reviewed and approved by someone other than its author; pull requests need a second approval before they merge; and production is logically separated from development and testing.
A documented incident management policy governs event handling. Incidents are tracked centrally to resolution, a post-incident analysis identifies the root cause, and the process is tested every year. No significant incidents were identified during the most recent attestation period.
Continuously by cloud-native monitoring and scanning, annually by an independent penetration test and a formal risk assessment, and annually by a third-party assessor who examines the whole system of controls. Leadership reviews the results twice a year.
Yes. The report is restricted to customers, prospective customers and their advisors, so it is shared on request rather than posted. Write to security@valere-health.com and we will send it under the usual terms.
Have concerns or questions about our security?
Ask a question, request the report, or report a potential security issue. It goes straight to the people responsible.