Trustro was designed from the ground up for healthcare data. Not retrofitted, not bolted on — architected for HIPAA from day one.
Current certifications and compliance status. We list only what we can substantiate.
Administrative, technical, and physical safeguards for protected health information. Trustro is fully HIPAA-compliant across all tiers.
Independent audit of security, availability, and confidentiality controls. Report available under NDA upon request.
Business Associate Agreements are available at every pricing tier, including Solo. No enterprise upgrade required.
HITRUST Common Security Framework certification is currently in progress. We do not claim HITRUST certification at this time.
How we protect patient health information at the infrastructure and application layers.
All patient health information is encrypted using AES-256 at rest and TLS 1.2+ in transit. Database-level encryption covers backups and replicas.
Four permission roles — Practitioner, Biller, Staff, and Administrator — each scoped to the minimum data access required for their function. Custom roles available on Multi-location tier.
Every access, modification, and export of patient data is logged with user identity, timestamp, and action. Audit logs are retained for seven years and cannot be modified or deleted.
Each practice operates in a logically isolated tenant. Data is never commingled across organizations. Row-level security enforced at the database layer.
Every account includes a sandbox environment with synthetic data for training and testing. Sandbox and production environments are fully isolated — no data crosses the boundary.
Sessions expire after 24 hours of inactivity. Re-authentication required for sensitive operations. Concurrent session limits enforced per user.
Clear boundaries around where patient data lives and how it moves.
This marketing site collects no protected health information. All clinical data resides in the HIPAA-scoped application environment, which is architecturally separate from marketing infrastructure.
Patient records, clinical notes, billing data, and scheduling information exist only inside the HIPAA-scoped application. Access requires authentication through the Trustro app with role-based permissions.
Active sessions expire after 24 hours. Idle timeout enforced. Re-authentication required before accessing or modifying patient records after session lapse.
Trustro is hosted on SOC 2-certified cloud infrastructure with data residency in the United States. Backups are encrypted and replicated across availability zones.
We conduct regular penetration testing through independent third-party firms. Vulnerability reports are reviewed within 24 hours, and critical findings are remediated on an expedited timeline.
Review our compliance documentation, request a BAA, or see our full list of subprocessors.