🚀 New: Real-time alerting & custom thresholds now available — See what's new

Enterprise-Grade Security & Compliance

Purpose-built for regulated industries. Every layer of Opslytica is designed to meet the strictest security and compliance requirements.

Certifications

Current Certifications & Standards

We maintain and pursue the certifications that matter most to healthcare and enterprise organizations.

Compliant

HIPAA Compliant

Full HIPAA compliance with Business Associate Agreements (BAA) available for all Enterprise customers. Our zero-PHI architecture ensures protected health information never touches our infrastructure.

In Progress

SOC 2 Type II

Currently undergoing SOC 2 Type II audit covering security, availability, and confidentiality trust service criteria. Expected completion Q2 2026. SOC 2 Type I report available upon request.

Compliant

GDPR Ready

Full GDPR compliance with data processing agreements, right to deletion, and data portability. EU data residency options available for organizations requiring data to remain within the European Union.

Planned 2026

ISO 27001

ISO 27001 certification is planned for H2 2026. Our information security management system (ISMS) already follows ISO 27001 controls and is being prepared for formal certification audit.

Under Review

FedRAMP

Pursuing FedRAMP Moderate authorization for federal agency deployment. Currently engaged with a Third Party Assessment Organization (3PAO) for initial readiness assessment.

Guaranteed

99.9% SLA

Guaranteed 99.9% uptime SLA backed by service credits. Our multi-region infrastructure with automated failover ensures your operational intelligence platform is always available when you need it.

Privacy

Zero PHI Architecture

Opslytica never stores, processes, or has access to protected health information.

HMAC-SHA256 Pseudonymization

All identifiable fields — member IDs, case IDs, patient identifiers — are pseudonymized via HMAC-SHA256 by your systems before data reaches Opslytica. The hashing is one-way and irreversible without your secret key.

Client-Managed Keys

Your organization retains sole custody of the HMAC secret key used for pseudonymization. Opslytica cannot reverse hashed identifiers. The key never leaves your infrastructure.

Deterministic Hashing

Same-input determinism means the same member ID always produces the same hash, preserving full analytical capability — trends, cohort analysis, SLA tracking — without exposing real identities.

No Reverse Lookup

Without your secret key, hashed tokens are meaningless. Even in the unlikely event of a data breach, no patient or member data can be recovered from our systems.

Infrastructure

Data Residency Options

Choose where your data lives to meet regulatory and organizational requirements.

US East (Virginia)

Primary region. Full redundancy with multi-AZ deployment, automated backups, and sub-millisecond failover. Ideal for East Coast and federal customers.

Available

US West (Oregon)

Secondary US region with full platform parity. Geographic redundancy for disaster recovery and lower latency for West Coast organizations.

Available

EU (Frankfurt)

European data residency for GDPR compliance. All data processing, storage, and backups remain within the EU. Planned for mid-2026 availability.

Coming Soon

Request Compliance Documentation

Need our SOC 2 report, BAA, or security questionnaire responses? Our compliance team is ready to support your vendor review process.

Hi there! 👋

How can we help you today?

Our team typically responds within a few hours during business hours.

Send us a message