CryoCaptures Security Initiatives

CryoCaptures is committed to protecting your data and your patients’ data. We continuously review and improve our security controls, policies, and procedures, with a particular focus on the requirements of the practices and IT teams who rely on us.

Data Encryption

CryoCaptures encrypts data in transit using TLS 1.2 or higher, enforced at our content delivery edge, with HTTP Strict Transport Security (HSTS) applied across the application. Subscriber data is encrypted at rest using industry-standard encryption, with keys managed by AWS Key Management Service (KMS). You can learn more here.

Continuous Vulnerability Management

CryoCaptures runs regular vulnerability assessments across our application and its dependencies. Findings are tracked in internal vulnerability reports and drive prioritized remediation, and dependencies are upgraded on a routine cadence to keep the platform current with upstream security fixes.

Cloud Infrastructure

The CryoCaptures platform is hosted on Amazon Web Services (AWS). AWS data centers undergo regular independent verification of their security, privacy, and compliance controls, including SOC 2 Type 2 and ISO 27001 assessments, and we run exclusively on HIPAA-eligible AWS services covered under a Business Associate Agreement. You can learn more here and here.

Multi-factor Authentication

Administrative access to the CryoCaptures application and internal tooling is protected by multi-factor authentication. One-time verification codes are time-limited and attempt-limited to resist brute-force and replay attacks.

Software Security

CryoCaptures is built following OWASP secure-development principles. Passwords are stored using modern hashing standards, and authentication endpoints are rate-limited to throttle abuse. Sessions are protected with industry-standard token-based authentication, and access is governed by role-based access control with strict organization-level data isolation, so each practice only ever sees its own data. File uploads are constrained by size limits and an allowlist of accepted file types.

User Access Controls

Administrative access to CryoCaptures infrastructure is restricted to explicitly allowlisted IP ranges. Our infrastructure configuration prohibits open administrative access as a hard rule, so no environment can be deployed without these controls in place.

Supply Chain Security

CryoCaptures applies strict controls to every third-party dependency in our software supply chain. Newly published package versions are subject to a quarantine period before they are eligible for use, our package manager itself is version-pinned and integrity-verified on install, and dependencies are constrained in what they are permitted to do at install time. Together these controls protect against compromised or malicious packages entering our builds.

Vendor Risk Management

CryoCaptures follows a defined process for evaluating and approving the vendors and service providers we rely on, with due-diligence steps covering data privacy and security posture. Vendor relationships are managed on an ongoing basis, and vendors handling sensitive data are governed by appropriate contractual safeguards.

Incident Response

CryoCaptures maintains a documented incident response plan with defined timelines for triage, investigation, and breach notification aligned with HIPAA requirements. Root-cause analyses are documented and retained for six years, and our infrastructure is continuously monitored for threats.

Backups and Data Recovery

Production databases are backed up automatically every day, with point-in-time recovery retained over an extended window. Object storage is versioned, allowing recovery from accidental deletion or corruption.

Disaster Recovery

CryoCaptures infrastructure is defined entirely as code. In the event of an outage, our environments can be rebuilt rapidly and reproducibly from version-controlled configuration.

Uptime and Resilience

CryoCaptures runs on a multi-Availability-Zone database deployment in production, with automatic failover, and application servers auto-scale to meet demand. This keeps the platform responsive as load changes and resilient to failures within a single zone. You can learn more here.

HIPAA Compliance

CryoCaptures is designed to support our customers’ HIPAA obligations. Access to electronic Protected Health Information (ePHI) is recorded in an immutable audit log and retained for a minimum of six years as required by law, and sensitive identifiers are automatically redacted from log records before they are stored. Role-based access control and organization-level isolation ensure PHI is only accessible to authorized users within the originating practice.