Security
The public compliance posture: how the platform is designed to handle protected data, isolate organizations, and keep access minimum-necessary and audited.
The platform is built for regulated transportation operators who handle protected health information. This section describes the security model at a high level: the design intent behind how the platform handles protected and personal data.
This is a posture document. It describes how the platform is designed to handle data and which controls are intended, not a representation that any specific control is currently audited, certified, or in production. Coverage is not compliance. This is not legal advice and not a certification. For implementation specifics for your organization, contact us.
Three principles
The security model rests on three ideas, described in plain language here and in more detail on the pages in this section.
- Protected data is handled directly, with proper controls. Rather than trying to wall off a "safe zone" and assume everything outside it is harmless, the platform treats protected data as present across the system and builds controls around it. In healthcare transportation, almost everything can be linked to a person's health-related trip, so handling it directly is the honest approach.
- Each organization is isolated. Your data is never commingled with another organization's data, and the isolation operates at more than one layer, not just by what the screen shows.
- Access is minimum-necessary and audited. Every person, agent, and process gets only the access its task needs, and access is recorded so it can be reviewed.
Cloud and regions
The entire platform runs on Google Cloud, on HIPAA-eligible infrastructure under a Business Associate Agreement. It operates in US regions only. The cloud provider's agreement covers the infrastructure; correct configuration and your own controls complete the picture.
In this section
Responsible disclosure
If you believe you have found a security issue, please report it to security@oneops.ai.
