EverRhythm logo

Enterprise-Grade Security,
Privacy by Design

Security controls are designed around strict separation between employment data and private personal Health information.

Comprehensive Protection

Security measures applied across every layer of the platform.

Multi-Factor Authentication

Work accounts support authenticator-app MFA, backup codes and organisation-wide MFA enforcement.

Single Sign-On (SSO)

Enterprise SSO configuration is available for SAML/OIDC deployments; provider activation is completed during enterprise implementation.

Encrypted Transport & Storage

EverRhythm uses encrypted transport and managed encrypted infrastructure. Deployment-specific controls are documented during security review.

Audit Logging

Administrative and sensitive cross-product actions are designed to be logged and auditable, with dedicated audit infrastructure across the platform.

Role-Based Access Control

Granular RBAC ensures users only access the precise data and features required for their organisational role.

Session Management

Organisation-configurable session timeouts and account security controls reduce persistent-session risk.

Compliance & Governance

Controls and governance are designed to support customer compliance obligations. Formal certifications are stated only when independently achieved.

GDPR & UK DPA

Privacy controls are designed with UK GDPR and EU GDPR principles in mind; customer-specific controller/processor obligations remain contract-dependent.

ISO 27001

Information-security controls, risk management and audit evidence are structured around an ISO 27001-aligned governance programme.

Independent Assurance

Independent assurance and customer security reviews can be supported as the enterprise programme matures; no unearned certification is implied.

Privacy by Design

Work is architected so account linking does not grant employers access to private employee Health records.

  • Separate Data Boundaries: Employment records and personal Health records use separate product permissions and access paths.
  • Minimum Data Collection: We only process data absolutely necessary for delivering the service.
  • Employee Data Ownership: Personal health records belong permanently to the employee, regardless of employment status.
  • Minimum-Cohort Aggregation: Work pulse organisation reporting suppresses groups below five contributors.
  • Granular Consent: Employees have explicit, line-item control over what anonymised data is shared for workplace research.

Data Residency

Data-residency requirements are assessed during enterprise implementation. Availability depends on the contracted hosting and provider configuration.

Incident Response

Security incidents are handled through the platform's incident-management and audit processes. Contractual notification commitments are defined in the applicable customer agreement and data-processing terms.

Questions about security?

Our security engineers are available to review architectures, complete vendor risk assessments, and discuss custom compliance requirements.