Purpose-built for regulated industries. Every layer of Opslytica is designed to meet the strictest security and compliance requirements.
We maintain and pursue the certifications that matter most to healthcare and enterprise organizations.
Full HIPAA compliance with Business Associate Agreements (BAA) available for all Enterprise customers. Our zero-PHI architecture ensures protected health information never touches our infrastructure.
Currently undergoing SOC 2 Type II audit covering security, availability, and confidentiality trust service criteria. Expected completion Q2 2026. SOC 2 Type I report available upon request.
Full GDPR compliance with data processing agreements, right to deletion, and data portability. EU data residency options available for organizations requiring data to remain within the European Union.
ISO 27001 certification is planned for H2 2026. Our information security management system (ISMS) already follows ISO 27001 controls and is being prepared for formal certification audit.
Pursuing FedRAMP Moderate authorization for federal agency deployment. Currently engaged with a Third Party Assessment Organization (3PAO) for initial readiness assessment.
Guaranteed 99.9% uptime SLA backed by service credits. Our multi-region infrastructure with automated failover ensures your operational intelligence platform is always available when you need it.
Opslytica never stores, processes, or has access to protected health information.
All identifiable fields — member IDs, case IDs, patient identifiers — are pseudonymized via HMAC-SHA256 by your systems before data reaches Opslytica. The hashing is one-way and irreversible without your secret key.
Your organization retains sole custody of the HMAC secret key used for pseudonymization. Opslytica cannot reverse hashed identifiers. The key never leaves your infrastructure.
Same-input determinism means the same member ID always produces the same hash, preserving full analytical capability — trends, cohort analysis, SLA tracking — without exposing real identities.
Without your secret key, hashed tokens are meaningless. Even in the unlikely event of a data breach, no patient or member data can be recovered from our systems.
Choose where your data lives to meet regulatory and organizational requirements.
Primary region. Full redundancy with multi-AZ deployment, automated backups, and sub-millisecond failover. Ideal for East Coast and federal customers.
AvailableSecondary US region with full platform parity. Geographic redundancy for disaster recovery and lower latency for West Coast organizations.
AvailableEuropean data residency for GDPR compliance. All data processing, storage, and backups remain within the EU. Planned for mid-2026 availability.
Coming SoonNeed our SOC 2 report, BAA, or security questionnaire responses? Our compliance team is ready to support your vendor review process.