Enterprise-Grade Security,
Privacy by Design
Security controls are designed around strict separation between employment data and private personal Health information.
Comprehensive Protection
Security measures applied across every layer of the platform.
Multi-Factor Authentication
Work accounts support authenticator-app MFA, backup codes and organisation-wide MFA enforcement.
Single Sign-On (SSO)
Enterprise SSO configuration is available for SAML/OIDC deployments; provider activation is completed during enterprise implementation.
Encrypted Transport & Storage
EverRhythm uses encrypted transport and managed encrypted infrastructure. Deployment-specific controls are documented during security review.
Audit Logging
Administrative and sensitive cross-product actions are designed to be logged and auditable, with dedicated audit infrastructure across the platform.
Role-Based Access Control
Granular RBAC ensures users only access the precise data and features required for their organisational role.
Session Management
Organisation-configurable session timeouts and account security controls reduce persistent-session risk.
Compliance & Governance
Controls and governance are designed to support customer compliance obligations. Formal certifications are stated only when independently achieved.
GDPR & UK DPA
Privacy controls are designed with UK GDPR and EU GDPR principles in mind; customer-specific controller/processor obligations remain contract-dependent.
ISO 27001
Information-security controls, risk management and audit evidence are structured around an ISO 27001-aligned governance programme.
Independent Assurance
Independent assurance and customer security reviews can be supported as the enterprise programme matures; no unearned certification is implied.
Privacy by Design
Work is architected so account linking does not grant employers access to private employee Health records.
- Separate Data Boundaries: Employment records and personal Health records use separate product permissions and access paths.
- Minimum Data Collection: We only process data absolutely necessary for delivering the service.
- Employee Data Ownership: Personal health records belong permanently to the employee, regardless of employment status.
- Minimum-Cohort Aggregation: Work pulse organisation reporting suppresses groups below five contributors.
- Granular Consent: Employees have explicit, line-item control over what anonymised data is shared for workplace research.
Data Residency
Data-residency requirements are assessed during enterprise implementation. Availability depends on the contracted hosting and provider configuration.
Incident Response
Security incidents are handled through the platform's incident-management and audit processes. Contractual notification commitments are defined in the applicable customer agreement and data-processing terms.
Questions about security?
Our security engineers are available to review architectures, complete vendor risk assessments, and discuss custom compliance requirements.