Connectors

Security

The public compliance posture: how the platform is designed to handle protected data, isolate organizations, and keep access minimum-necessary and audited.

The platform is built for regulated transportation operators who handle protected health information. This section describes the security model at a high level: the design intent behind how the platform handles protected and personal data.

This is a posture document. It describes how the platform is designed to handle data and which controls are intended, not a representation that any specific control is currently audited, certified, or in production. Coverage is not compliance. This is not legal advice and not a certification. For implementation specifics for your organization, contact us.

Three principles

The security model rests on three ideas, described in plain language here and in more detail on the pages in this section.

  • Protected data is handled directly, with proper controls. Rather than trying to wall off a "safe zone" and assume everything outside it is harmless, the platform treats protected data as present across the system and builds controls around it. In healthcare transportation, almost everything can be linked to a person's health-related trip, so handling it directly is the honest approach.
  • Each organization is isolated. Your data is never commingled with another organization's data, and the isolation operates at more than one layer, not just by what the screen shows.
  • Access is minimum-necessary and audited. Every person, agent, and process gets only the access its task needs, and access is recorded so it can be reviewed.

Cloud and regions

The entire platform runs on Google Cloud, on HIPAA-eligible infrastructure under a Business Associate Agreement. It operates in US regions only. The cloud provider's agreement covers the infrastructure; correct configuration and your own controls complete the picture.

In this section

Data handling

How data is classified, what is logged, and how sensitive fields are protected.

Access and audit

Role-based access, tenant isolation, and append-only audit logging.

AI and PHI

How AI features handle protected data and stay inside the operator's scope.

Responsible disclosure

If you believe you have found a security issue, please report it to security@oneops.ai.