Our Approach to Security

.png)
At AidKit, we know that trust is the foundation of every program we support. Protecting the confidentiality, integrity, and availability of your data is not just a regulatory requirement—it is a core commitment we make to our clients and the individuals they serve.

We maintain a comprehensive, risk-based information security and privacy program.
By embedding security into our daily operations and our software development lifecycle, we ensure that we stay ahead of evolving threats and technology changes. Industry-Standard Compliance.
Our security program is designed to meet rigorous, recognized industry standards, providing you with confidence that your data is managed with the highest level of care.
Our security program is designed to meet rigorous, recognized industry standards, providing you with confidence that your data is managed with the highest level of care.
SOC 2 Type II
We undergo regular, independent SOC 2 Type II examinations to verify that our security, availability, and confidentiality controls are both well-designed and operating effectively.
HIPAA Compliance
For programs involving Protected Health Information (PHI), we maintain safeguards that map directly to the requirements of the HIPAA Security and Privacy Rules.
Continuous Monitoring
We use automated, real-time compliance tools (such as Vanta) to monitor our systems, configurations, and access controls around the clock.
Penetration Testing
We engage third-party experts to conduct regular, independent penetration tests, ensuring our systems are rigorously evaluated for potential vulnerabilities and that any findings are promptly remediated.
Key Security Measures
We protect your data through a "defense-in-depth" strategy that spans administrative, technical, and physical safeguards:
Encryption Everywhere
We use industry-standard AES-256 encryption for data at rest and TLS 1.2 or higher for data in transit, ensuring information remains protected and unreadable to unauthorized parties.
Access Control & Identity
We operate on the principle of "least privilege." Access to sensitive data and production systems is restricted based on job function, protected by multi-factor authentication, and audited regularly. We also support single sign-on (SSO) integrations for seamless, secure user management.
Secure Infrastructure
Our platform is hosted in secure, cloud-native environments (AWS) that provide built-in network isolation, firewall protections, and advanced threat detection.
Secure Development
Security is a part of our product DNA. We incorporate privacy-by-design principles, rigorous code reviews, automated testing, and independent penetration testing into every phase of our software development.
Incident Response
While we strive to prevent incidents, we maintain a robust, tested Incident Response Plan. We are committed to transparency and will notify our clients promptly should any verified security incident occur.
Data Privacy & Stewardship.
We believe your data belongs to you.
Data Minimization
We only collect and process the data necessary to provide our services and support your program.
No Data Selling
AidKit does not sell Client Data.
Lifecycle Management
We apply strict retention policies and, at the conclusion of our services, return or securely delete data in accordance with our agreements.