SECURITY

Secure by design

Protecting patient data is not a feature we added, it is how Sandy is built. We handle some of the most sensitive data in healthcare, and we treat it that way at every layer.

AICPA SOC 2
SOC 2 Type II compliant

Independently audited for security, availability, and confidentiality, and reviewed periodically by third parties.

HIPAA
HIPAA adherent

Full adherence to the Privacy, Security, and Breach Notification Rules, on U.S.-based, HIPAA-compliant infrastructure.

Protected at every layer

Encryption

AES-256 at rest and TLS 1.2+ in transit, for all data.

Access management

Role-based permissions, multi-factor authentication, and least-privilege by default. Every access is logged.

Continuous monitoring

Controls are tested and monitored continuously, so they stay effective as the platform evolves.

In-house de-identification

Sandy strips PHI with its own models, before data is ever used to improve the product.

How it works

Built for healthcare, at every layer

Designed for healthcare

U.S.-based, HIPAA-compliant infrastructure, with security and compliance embedded in daily operations, not treated as periodic audits.

Privacy at every layer

We collect only what is necessary, and every new feature goes through a security and privacy review before release.

Security that scales with you

As threats evolve and you grow, Sandy strengthens safeguards, watches for emerging risks, and keeps tested incident response protocols.

See the full picture in the Trust Center

Current reports, subprocessors, and controls are kept up to date there as the platform grows.

Visit the Trust Center