The Waiver Academy
← Back to Why Waiver Academy

Trust & Security

Enterprise-Grade Security for Your Agency's Most Sensitive Data

Your staff data, compliance records, and training history are protected with bank-level encryption, HIPAA-compliant infrastructure, and continuous 24/7 monitoring.

Security and trust

99.9%

Uptime SLA

HIPAA

Compliant

AES-256

Encryption

24/7

Security Monitoring

Security Layers

Security Built for Healthcare Compliance

Every layer of our platform is designed to meet the strictest healthcare data security and privacy requirements.

HIPAA Compliance

Full HIPAA compliance with signed BAAs available. All PHI and PII is encrypted at rest (AES-256) and in transit (TLS 1.3).

SOC 2 Type II

Independently audited security controls verified through annual SOC 2 Type II certification — available for customer review.

Continuous Monitoring

Real-time threat detection, intrusion prevention, and 24/7 security operations center monitoring with automated incident response.

Data Residency

All data is stored in US-based data centers with geographic redundancy. No data is stored or processed outside the United States.

Role-Based Access

Granular role-based access controls (RBAC) ensure staff only access the data and features appropriate to their role.

Incident Response

Documented incident response procedures with customer notification within 72 hours of any security event — exceeding HIPAA requirements.

Data Privacy

Your data stays yours — always

We never sell, share, or use your agency's data for any purpose other than providing you with the platform. Every customer is isolated in their own secure environment with role-based access controls and complete data ownership.

  • Data isolation per agency — zero cross-tenant access ever
  • Role-based access controls (RBAC) with granular permissions
  • Full audit logs of every user action for compliance review
  • GDPR-aligned data handling and deletion practices
  • Right to data export and deletion upon contract termination
Learn More
Your data stays yours — always

Certifications & Standards

Built to Meet Every Enterprise & Government Security Standard

HIPAA compliant with signed BAAs
SOC 2 Type II certified (annual audit)
AES-256 encryption at rest
TLS 1.3 encryption in transit
WCAG 2.1 AA accessibility compliant
GDPR-aligned data practices
SAML 2.0 / SSO identity integration
SCIM user provisioning
Multi-factor authentication (MFA)
IP allowlisting for agency networks
Full audit logs of every user action
US-based data residency

Identity & Access Management

Enterprise identity and access management

Integrate with your existing identity provider for seamless, secure access across your organization — without managing separate credentials or access tokens.

  • SAML 2.0 / SSO integration with any identity provider
  • SCIM automated user provisioning and deprovisioning
  • Multi-factor authentication (MFA) required or optional
  • IP allowlisting for agency-controlled network access
  • Session timeout and idle user management policies
Learn More
Enterprise identity and access management

Let's get started

Your data is safe with us — we'll prove it.

Request our security documentation package and SOC 2 report today.