Security & compliance

Defense-grade by design.

Aegis is built to handle some of the most sensitive data in healthcare — including military patient imaging — and to prove it at every step. Encryption, isolation, and auditability are the foundation, not an add-on.

HIPAA Compliant

HIPAA-compliant by architecture. Encryption end to end, Business Associate Agreements across the chain, data minimization that keeps PHI out of billing, and an immutable audit trail — engineered for U.S. HIPAA and DoD IL4/IL5.

U.S.-based organizations only. Data is processed and stored within U.S. sovereign cloud boundaries.

Controls

Controls that hold up to scrutiny.

Every safeguard maps to a recognized framework — and to an exportable record auditors can verify.

  • End-to-end encryption, in transit and at rest
  • Customer-managed keys (BYOK) — you hold control
  • Architected for DoD IL4 / IL5 and HIPAA boundaries
  • Bitcoin-anchored, tamper-evident audit (only a hash leaves)
  • Business Associate Agreements across the chain
  • Strict data minimization — billing never touches PHI
HIPAA
DoD IL4 / IL5-ready
FedRAMP-aligned
AES-256 · BYOK
BAA ready
SOC 2 (in progress)
Data lifecycle

From release to destruction — controlled and provable.

PHI enters under the owner's keys and leaves on a schedule the owner sets. Nothing lingers.

  1. 01

    Encrypted at rest

    On arrival, each study is encrypted under customer-managed keys. Access is scoped to a single authorized recipient.

  2. 02

    Time-boxed access

    Release carries an auto-destruct window and a view policy. Access is metered and logged; downloads and exports are blocked.

  3. 03

    Irreversible destruction

    When the window is reached — or on demand — the payload is destroyed for good, and the disposal is recorded in the audit trail.

Need a DPA or BAA to evaluate?

We'll provide the agreements and a controls summary for your security review.

Request DPA / BAA

NDA available for technical deep dives. U.S.-based organizations only.