SECURITY

Secure by design

Protecting patient data is not a feature we added, it is how Sandy is built. We handle some of the most sensitive data in healthcare, and we treat it that way at every layer.

AICPA SOC 2
SOC 2 Type II compliant

Independently audited for security, availability, and confidentiality, and reviewed periodically by third parties.

HIPAA
HIPAA adherent

Full adherence to the Privacy, Security, and Breach Notification Rules, on U.S.-based, HIPAA-compliant infrastructure.

Protected at every layer

Encryption

AES-256 at rest and TLS 1.2+ in transit, with keys rotated on a set schedule.

Access management

Role-based permissions, MFA, and least-privilege by default, with every access logged.

Continuous monitoring

Controls are tested and monitored continuously, with tested incident response ready.

In-house de-identification

Sandy strips PHI with its own models before data is ever used. Nothing identifiable leaves its boundary.

How it works

Built for healthcare, at every layer

Designed for healthcare

U.S.-based, HIPAA-compliant infrastructure, with security and compliance embedded in daily operations, not treated as periodic audits.

Privacy at every layer

We collect only what is necessary, and every new feature goes through a security and privacy review before release.

Security that scales with you

As threats evolve and you grow, Sandy strengthens safeguards, watches for emerging risks, and keeps tested incident response protocols.

See the full picture in the Trust Center

Current reports, subprocessors, and controls are kept up to date there as the platform grows.

Visit the Trust Center