Builds and maintains the environment
- Provisions cloud infrastructure and CI/CD
- Hardens, scans, patches, and observes
- Builds secure integration infrastructure
- Does not host the platform or hold PHI
For the Chief Information Security Officer
Hardened infrastructure. Bounded access. Continuous evidence.
The platform is built inside your company-owned cloud infrastructure that All Hail builds and hardens. SSO, VPN, TLS, encryption, continuous scanning, patching, auditability, and governed delivery operate as one security model.
Control to evidence
Production experience
The Operating Platform and cloud architecture have operated inside audited, customer-owned healthcare environments with HIPAA-aligned controls and evidence.
Environment ownership
Security and compliance are built into the Operating Platform. Its HIPAA-aligned controls, evidence, and operating practices have successfully supported independent third-party HIPAA audits, internal and third-party HIPAA risk assessments, SOC 2 Type II examinations, and HITRUST certification.
Cloud security posture
We provision and harden the cloud infrastructure inside the company's environment. Continuous vulnerability scanning is built into the account, with patching across the ecosystem on daily or weekly cadences.
Company-owned security foundation
Cloud baselines, identity, network boundaries, encryption, logging, and deployment controls are established as part of implementation.
Continuous scanning, recurring patching, remediation, and retained operational evidence maintain the posture after deployment.
Identity and access
SSO establishes human identity. Roles, tenants, context, and permissions bound the work. Services and agents receive only the access, tools, and information their defined jobs require.
Authorization path
People receive access based on role, tenant, context, workflow, and the specific action being performed.
VPN and TLS secure system-to-system connectivity. Access remains explicit, bounded, and observable.
Data protection
Encrypt data at rest and in transit. Carry tenant separation, RBAC, audit history, recoverable records, and explicit trust boundaries through every stage of the data lifecycle.
Data lifecycle
VPN, TLS, or managed SFTP trust boundary
Encryption at rest and logical tenant partitioning
SSO, RBAC, and application context
Authorized action and audit history
TLS or managed SFTP data exchange
Recoverability under company policy
Continuous controls
Access, infrastructure scans, patching, deployments, application actions, exceptions, and approvals create reviewable evidence. Vanta can connect relevant evidence to the broader compliance program.
Control and evidence matrix
| Activity | Operating control | Evidence produced | Review path |
|---|---|---|---|
| Access | SSO, role, tenant boundary | Actor, scope, time, context | Access and exception review |
| Cloud posture | Hardened baseline, continuous scan | Findings, status, remediation | Infrastructure security review |
| Infrastructure maintenance | Daily or weekly patching | Patch status and change history | Operational review |
| Deployment | CI/CD, review, isolated environment | Build, test, approval, release | Engineering and compliance review |
| Data exchange | VPN, TLS, managed SFTP | Connection and transfer records | Integration and access review |
| Application action | Permission and workflow control | Actor, action, state, disposition | Audit and exception review |
Intelligent work
Every agent receives an identity, a defined job, bounded context, approved tools, evaluation, retained evidence, escalation, and explicit human control points.
Governed agent record
Certification captures a point in time. Strong architecture keeps producing the controls and evidence required to operate securely.
One platform. Different responsibilities.