Security
Last Updated: June 1, 2026
1. Our Commitment
At SolidHealth.AI, security is foundational to everything we build. We are committed to protecting the confidentiality, integrity, and availability of your data — especially health information — through industry-leading practices and continuous improvement.
2. Infrastructure Security
- Cloud-hosted on SOC 2 Type II certified infrastructure
- Network segmentation and firewall protection
- DDoS mitigation and intrusion detection systems
- Regular vulnerability scanning and penetration testing
- Automated patching and configuration management
3. Data Protection
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Strict access controls with role-based permissions
- Data isolation between tenants
- Regular encrypted backups with tested recovery procedures
- Secure key management with hardware security modules
4. Application Security
- Secure development lifecycle (SDLC) with security reviews
- Static and dynamic application security testing (SAST/DAST)
- Dependency vulnerability monitoring
- Input validation and output encoding
- Rate limiting and abuse prevention
5. Authentication & Access
- Multi-factor authentication (MFA) support
- Single sign-on (SSO) integration for enterprise customers
- Session management with automatic timeout
- Audit logging of all administrative actions
- Principle of least privilege for internal access
6. Compliance
- HIPAA compliant — Business Associate Agreements available
- SOC 2 ready
- Regular third-party security assessments
- Employee security awareness training
- Incident response plan with defined SLAs
7. Incident Response
We maintain a documented incident response plan that includes detection, containment, eradication, recovery, and post-incident review. In the event of a data breach affecting your information, we will notify you in accordance with applicable law and our contractual obligations.
8. Responsible Disclosure
If you discover a security vulnerability in our Services, please report it responsibly to security@solidhealth.ai. We appreciate the security research community and will acknowledge valid reports.
9. Contact
For security-related questions or concerns, reach our security team at security@solidhealth.ai.