Security & Compliance

Security Standards & Compliance

STFE is built on a security-first foundation. Every clinical record is hash-sealed (tamper-evident). Every access is logged. Every byte is encrypted.

Certifications & Attestations

🛡️
HIPAA
Full HIPAA compliance. BAA available for all customers. Business Associate under 45 CFR Parts 160 & 164.
Active
🔒
SOC 2 Type II
Independent audit of security, availability, and confidentiality controls underway. Report available under NDA once complete.
In Progress
☁️
AWS HIPAA-Eligible
All production infrastructure on AWS HIPAA-eligible services. AWS BAA in place.
Active

Cryptographic Audit Integrity

STFE's most distinctive security feature is the SHA-256 tamper-evident hash-sealing of every clinical evaluation record. This is not a standard feature of any other SNF or CAH software.

Infrastructure Security

🔐 Encryption at Rest

AES-256 encryption on all data stores. AWS RDS with storage encryption. S3 server-side encryption.

🔒 Encryption in Transit

TLS 1.3 enforced on all connections. HSTS headers. Certificate pinning on mobile clients.

🌐 Network Isolation

Production workloads in private VPC subnets. No direct internet access to database or cache layers. NAT gateway for outbound-only traffic.

🔑 Secrets Management

All credentials stored in AWS Secrets Manager. No hardcoded secrets in application code. Automatic rotation.

📊 Monitoring & Alerting

Real-time alerting on authentication anomalies, access control violations, and abnormal API patterns. 24/7 alert coverage.

🚀 Container Security

AWS ECS Fargate (serverless containers). No persistent compute instances. Image vulnerability scanning on every build.

Access Controls

Application Security

Business Continuity

Employee Security

🔍 Report a Security Vulnerability

STFE operates a responsible disclosure program. If you discover a security vulnerability in our platform, please contact us before public disclosure. We will acknowledge receipt within 24 hours and provide a resolution timeline within 5 business days.

Email: security@stfe.io
PGP Key: Available on request for encrypted submissions
24/7 Hotline: +1 (302) 555-1911

We do not pursue legal action against security researchers who act in good faith and follow responsible disclosure practices.

Request Security Documentation

The following security documents are available to customers and prospective customers under NDA:

Contact security@stfe.io to request security documentation.

Last Updated: May 4, 2026  |  Document Version: 1.0