Data Security

Last updated: May 1, 2026(version 2026-05-01)

For our live compliance posture, sub-processor list, certifications, and security controls, visit our Trust Center .

Security Overview

UM-AI (operated by SSP Development LLC) applies a defense-in-depth security model covering encryption, access control, continuous monitoring, vulnerability management, and incident response. All controls are aligned with HIPAA Security Rule (45 CFR Part 164), NIST SP 800-53, and the SOC 2 Trust Services Criteria (Security, Availability, Confidentiality).

Clinical data submitted for AI evaluation is processed transiently in memory to produce results and is not persisted beyond the minimum required for audit-log integrity. Customer organizations are logically isolated from one another at the application and database layer.

Encryption

In Transit — TLS 1.3

All communication between clients and the UM-AI platform is encrypted using TLS 1.3. HTTP traffic is automatically redirected to HTTPS. Older protocol versions (TLS 1.0, 1.1) are disabled at the infrastructure level (Replit). Certificate management is handled by Replit's SOC 2–certified hosting layer.

At Rest — AES-256

All data persisted to the database is encrypted at rest using AES-256 encryption managed by Neon (Neondatabase, Inc.), our serverless PostgreSQL provider. Neon holds SOC 2 Type 2 attestation and enforces encryption at the storage layer transparently to the application.

Key Management

Encryption keys are managed by Neon and Replit respectively. Application-level secrets (API keys, session secrets) are stored in Replit's encrypted secrets store and are never committed to source control or logged.

Access Control

Role-Based Access Control (RBAC)

UM-AI enforces four user roles with strictly scoped permissions:

  • User — Submit and view own evaluations only
  • Manager — View all evaluations within their organization; manage team members
  • UMdirector — Full evaluation visibility; configure protocols; export reports
  • Super Admin — Cross-organization administration; system configuration; audit access

Access across organizations is strictly prohibited at the API layer. Every request is validated against the authenticated user's organization and role before data is returned.

Multi-Factor Authentication (MFA)

EHR-integrated users authenticate via VIM Canvas SDK SSO which enforces MFA at the identity provider (Inovalon) level. Direct platform users use session-based authentication with bcrypt password hashing (cost factor 12). MFA enforcement for direct-login accounts is on the roadmap and tracked in our Vanta program.

Session Management

Sessions are stored server-side in the encrypted PostgreSQL database via connect-pg-simple. Session tokens are HttpOnly, Secure-flag, and SameSite=Strict. Sessions expire after inactivity. VIM EHR sessions persist across page reloads within the authenticated EHR context using signed session validation.

Least Privilege

Database credentials follow the principle of least privilege. The application database user has no DDL privileges in production. Administrative database access requires separate, time-limited credentials.

Monitoring & Audit Logging

What Is Logged

UM-AI maintains a comprehensive security audit log capturing:

  • Authentication events (login, logout, failed attempts, session creation/expiry)
  • Authorization decisions (access granted/denied, role escalation attempts)
  • AI evaluation submissions and results (user, org, specialty, decision — no raw PHI)
  • Administrative actions (user creation, role changes, protocol edits)
  • Billing and subscription events
  • Security-relevant HTTP requests (rate-limit triggers, anomalous patterns)
  • Deployment events with commit SHA and timestamp

Retention — 6-Year HIPAA Minimum

Audit logs are retained for a minimum of six years per HIPAA Security Rule §164.316(b)(2)(i). PHI is never stored in log entries; clinical input fields are sanitised to structured metadata (specialty, urgency level, decision outcome) before logging.

Continuous Monitoring

An in-process Intrusion Detection System (IDS) inspects all inbound HTTP traffic for anomalous patterns including SQL injection, cross-site scripting, path traversal, and brute-force login attempts. Rate limiting is enforced at the API gateway level. Security alerts are written to the audit log and escalated to the security team at security@umgpt.ai.

Vulnerability Management

Assessment Cadence

  • Dependency vulnerability scans run on every code push (npm audit, SAST)
  • Annual external penetration test against the production environment
  • Quarterly internal security review of all access controls and audit log patterns
  • Firewall ruleset review: annually (documented in Vanta)

Patch Management

Critical and high-severity dependency patches are applied within 30 days of disclosure. Medium/low patches are batched in the regular release cycle. Security patches to infrastructure providers (Neon, Replit) are applied automatically by those providers under their SOC 2–certified patch management programs.

Responsible Disclosure

Security researchers who discover vulnerabilities in UM-AI are encouraged to report them to security@umgpt.ai. We acknowledge reports within 2 business days and follow coordinated disclosure practices.

Incident Response

UM-AI maintains a formal Incident Response Plan (IRP) reviewed annually and tested via tabletop exercises. The plan covers detection, containment, eradication, recovery, and post-incident review phases.

HIPAA Breach Notification

In the event of a confirmed breach involving Protected Health Information (PHI), UM-AI will notify affected Covered Entities within 72 hours of discovering the breach, consistent with HIPAA Breach Notification Rule (45 CFR §§164.400–414) and the terms of our Business Associate Agreements. Individual notification timelines follow the requirements of applicable law.

Contact

UM-AI shares data with a limited set of sub-processors as necessary to provide the service. All sub-processors handling PHI are covered by a Business Associate Agreement (BAA) or equivalent contractual protections. The live sub-processor list is maintained in our Trust Center .