Security & compliance

Compliant by design.

Aegis is built to handle some of the most sensitive data in healthcare, regulated patient imaging, and to prove it at every step. Encryption, isolation, and auditability are foundational, not add-ons.

HIPAA

HIPAA-aligned by architecture. Encryption end to end, Business Associate Agreements across the chain, data minimization that keeps PHI out of billing, and a tamper-evident audit trail, mapped to the HIPAA Security Rule safeguards.

Controls

Controls that hold up to scrutiny.

Every safeguard maps to a recognized framework, and to an exportable record auditors can verify.

  • End-to-end encryption, in transit and at rest
  • Per-study envelope encryption (AES-256); keys destroyed on expiry
  • Mapped to the HIPAA Security Rule safeguards
  • Bitcoin-anchored, tamper-evident audit (only a hash leaves)
  • Business Associate Agreements across the chain
  • Strict data minimization: billing never touches PHI
HIPAA-aligned
AES-256 per-study keys
BAA ready
Data lifecycle

From release to destruction: controlled and provable.

PHI enters under the owner's keys and leaves on a schedule the owner sets. Nothing lingers.

  1. 01

    Encrypted at rest

    On arrival, each study is sealed with its own per-study key (AES-256). Access is scoped to a single authorized recipient.

  2. 02

    Time-boxed access

    Release carries an auto-destruct window and a view policy. Access is metered and logged; downloads and exports are blocked.

  3. 03

    Irreversible destruction

    When the window is reached, or on demand, the payload is destroyed for good, and the disposal is recorded in the audit trail.

Need a DPA or BAA to evaluate?

We'll provide the agreements and a controls summary for your security review.

Request DPA / BAA

Public security overview available; NDA for technical deep dives.