HIPAA-Capable Standard
While HealStroke's consumer offering is not governed by HIPAA, we engineer our systems to a HIPAA-capable security standard to protect your sensitive health data.
Encryption Standards
Data in transit is secured using modern TLS 1.2+ protocols.
Data at rest is secured using AES-256-class encryption. We utilize managed Key Management Services (KMS), perform key rotation, maintain encrypted backups, and utilize field-level encryption for extremely sensitive information where appropriate.
Access Controls and Auditing
Administrative access to production systems requires Multi-Factor Authentication (MFA). We operate on a principle of least privilege, utilize short-lived credentials, and maintain strict audit logging for access to systems containing personal information.
Environment Isolation
We maintain strict environment isolation. Production health information is never used in developer test or staging environments.
Incident Response
We maintain a formal incident response plan and vulnerability management program. Vendor security and subprocessor risk are assessed prior to engagement.
Vulnerability Disclosure
If you believe you have found a security vulnerability, please contact our security team at security@stroke.technology. We appreciate responsible, coordinated disclosure and ask that you do not publicly disclose unresolved issues.