Secure by design
Protecting patient data is not a feature we added, it is how Sandy is built. We handle some of the most sensitive data in healthcare, and we treat it that way at every layer.

Independently audited for security, availability, and confidentiality, and reviewed periodically by third parties.

Full adherence to the Privacy, Security, and Breach Notification Rules, on U.S.-based, HIPAA-compliant infrastructure.
Protected at every layer
Encryption
AES-256 at rest and TLS 1.2+ in transit, for all data.
Access management
Role-based permissions, multi-factor authentication, and least-privilege by default. Every access is logged.
Continuous monitoring
Controls are tested and monitored continuously, so they stay effective as the platform evolves.
In-house de-identification
Sandy strips PHI with its own models, before data is ever used to improve the product.
How it worksBuilt for healthcare, at every layer
Designed for healthcare
U.S.-based, HIPAA-compliant infrastructure, with security and compliance embedded in daily operations, not treated as periodic audits.
Privacy at every layer
We collect only what is necessary, and every new feature goes through a security and privacy review before release.
Security that scales with you
As threats evolve and you grow, Sandy strengthens safeguards, watches for emerging risks, and keeps tested incident response protocols.
See the full picture in the Trust Center
Current reports, subprocessors, and controls are kept up to date there as the platform grows.
Visit the Trust Center