Our Approach to Security

AICPA SOC certification seal for service organizations with website aicpa.org/soc4so.
Insight Assurance AidKit SOC 2 Type 2 Compliant badge for 2025.
At AidKit, we know that trust is the foundation of every program we support. Protecting the confidentiality, integrity, and availability of your data is not just a regulatory requirement—it is a core commitment we make to our clients and the individuals they serve.

We maintain a comprehensive, risk-based information security and privacy program.

By embedding security into our daily operations and our software development lifecycle, we ensure that we stay ahead of evolving threats and technology changes. Industry-Standard Compliance.

Our security program is designed to meet rigorous, recognized industry standards, providing you with confidence that your data is managed with the highest level of care.

SOC 2 Type II

We undergo regular, independent SOC 2 Type II examinations to verify that our security, availability, and confidentiality controls are both well-designed and operating effectively.

HIPAA Compliance

For programs involving Protected Health Information (PHI), we maintain safeguards that map directly to the requirements of the HIPAA Security and Privacy Rules.

Continuous Monitoring

We use automated, real-time compliance tools (such as Vanta) to monitor our systems, configurations, and access controls around the clock.

Penetration Testing

We engage third-party experts to conduct regular, independent penetration tests, ensuring our systems are rigorously evaluated for potential vulnerabilities and that any findings are promptly remediated.

Key Security Measures

We protect your data through a "defense-in-depth" strategy that spans administrative, technical, and physical safeguards:

Encryption Everywhere

We use industry-standard AES-256 encryption for data at rest and TLS 1.2 or higher for data in transit, ensuring information remains protected and unreadable to unauthorized parties.

Access Control & Identity

We operate on the principle of "least privilege." Access to sensitive data and production systems is restricted based on job function, protected by multi-factor authentication, and audited regularly. We also support single sign-on (SSO) integrations for seamless, secure user management.

Secure Infrastructure

Our platform is hosted in secure, cloud-native environments (AWS) that provide built-in network isolation, firewall protections, and advanced threat detection.

Secure Development

Security is a part of our product DNA. We incorporate privacy-by-design principles, rigorous code reviews, automated testing, and independent penetration testing into every phase of our software development.

Incident Response

While we strive to prevent incidents, we maintain a robust, tested Incident Response Plan. We are committed to transparency and will notify our clients promptly should any verified security incident occur.

Data Privacy & Stewardship.
We believe your data belongs to you.

Data Minimization

We only collect and process the data necessary to provide our services and support your program.

No Data Selling

AidKit does not sell Client Data.

Lifecycle Management

We apply strict retention policies and, at the conclusion of our services, return or securely delete data in accordance with our agreements.