πŸ”’ Your Data is Safe

Enterprise-grade security built for California care facilities

HIPAA-Ready

Built with the security features required to protect resident health information

Working Toward SOC 2

Internal readiness work complete β€” now selecting an independent audit firm for our Type I assessment

Bank-Level Encryption

Your data is encrypted the same way banks protect financial information

How We Keep Your Data Safe

Security explained in plain English

πŸ” Your Data is Locked Away

Think of Kura Center like a building with separate locked filing cabinets for each facility. Your facility's cabinet has its own unique key. Even if someone broke into the building, they couldn't open your cabinet without your specific key. That's how we keep your data completely separate from other facilities.

πŸ“ Every Action is Recorded

Imagine a security camera that records everything, but the recordings are locked in a safe that can't be opened or erased. That's our audit trail. Every time someone views a resident's record, documents a service, or makes a change, it's permanently recorded with the date, time, and who did it. Perfect for inspections.

πŸ”’ Everything is Encrypted

Encryption is like putting your data in a safe. Even if someone stole your computer or intercepted your internet connection, all they'd see is scrambled gibberish. We use the same encryption that banks use to protect financial information.

πŸ‘₯ Staff Only See What They Need

Not everyone needs access to everything. Administrators see everything, managers see schedules and reports, and staff see their own schedules and the residents they work with. Just like you wouldn't give every employee the keys to every room in your facility.

What This Means For You

βœ“ Pass Inspections with Confidence

When licensing or DDS shows up, you can pull complete, unalterable records in minutes. No scrambling for paper files.

βœ“ Protect Resident Privacy

Residents and families can trust that their information is secure and only seen by authorized staff.

βœ“ Avoid Data Breaches

Your data is more secure in Kura Center than in filing cabinets or spreadsheets on staff computers.

βœ“ Meet QIP Requirements

Complete audit trails and EVV compliance built-inβ€”exactly what DDS requires for QIP.

βœ“ Sleep Better at Night

Know that your facility's data is protected by the same security standards used by hospitals and banks.

βœ“ Simple for Staff

All this security happens automatically. Staff just do their jobsβ€”the system handles the security.

Common Questions

What if my computer gets stolen?

Your data is safe. It's stored in secure data centers, not on your computer. You can log in from any device and your data is still there. Just change your password and the thief can't access anything.

What if Kura Center gets hacked?

We have multiple layers of protection. Even if someone broke through one layer, your facility's data is isolated and encrypted. They'd need your specific encryption keys to read anythingβ€”and those are stored separately and securely.

Can staff delete records to hide mistakes?

No. Records are permanent and cannot be deleted or altered. If someone makes a correction, both the original and the correction are saved with timestamps. This protects you during inspections.

What about HIPAA? Will you sign a BAA with my facility?

Kura Center is built HIPAA-ready, and everything runs on infrastructure covered by a signed Business Associate Agreement with AWS. If your facility requires a BAA with Kura Center, contact us β€” we'll work through it with you.

What if I want to stop using Kura Center?

You own your data. You can export everything at any time in standard formats. No vendor lock-in, no hassles.

Security Overview

The answers your IT reviewer or Regional Center will ask for β€” at a glance

At a Glance

HostingAWS (us-west-2), signed Business Associate Agreement in place
EncryptionAES-256 at rest, TLS 1.3 in transit
Tenant isolationEnforced at the database layer (PostgreSQL Row Level Security)
Access controlRole-based permissions, MFA (SMS or authenticator app), automatic session timeout
Audit trailAppend-only, tamper-proof, retained 7 years (Title 22)
Backups & recoveryAutomated daily backups, multi-zone failover, 4-hour recovery objective
HIPAAHIPAA-ready architecture aligned to the Security Rule's technical safeguards
SOC 2Readiness complete; independent Type I audit firm selection underway

Completing a security questionnaire or vendor review? Contact us β€” we'll fill it out with you.

Multi-Tenant Data Isolation

Standard: PostgreSQL Row Level Security (RLS), enforced on every table holding facility data (100+)

Each facility's records are isolated by the database itself, not just by application code. Every query is automatically restricted to the requesting facility, so even an application-level vulnerability cannot expose one facility's data to another.

Encryption

At Rest: AES-256-GCM

  • AWS RDS encryption enabled on all database instances
  • EBS volumes encrypted with AWS KMS
  • S3 buckets encrypted with SSE-KMS
  • Backup snapshots encrypted

In Transit: TLS 1.3

  • HTTPS enforced for all connections
  • HSTS enabled with 1-year max-age
  • Fully browser-based β€” no software to install or patch on facility devices
  • Database connections use SSL/TLS

Immutable Audit Trails

Implementation: Append-only audit log

Every create, read, update, and delete operation is logged with the acting user, facility, action, affected record, change details, IP address, and timestamp. The application's database role is denied UPDATE and DELETE on the log table, so audit records cannot be altered or removed β€” corrections are recorded as new entries alongside the original. Logs are retained for 7 years per California Title 22 requirements.

HIPAA Readiness

Current Status: HIPAA-Ready Architecture

Kura Center is built with HIPAA-ready infrastructure and implements technical safeguards required by HIPAA Security Rule.

Β§164.312(a)(1) - Access Control

  • Unique user identification (UUID-based user accounts)
  • Emergency access procedures (admin override with audit trail)
  • Automatic logoff (30-minute session timeout)
  • Encryption and decryption (AES-256-GCM)

Β§164.312(b) - Audit Controls

  • Immutable audit logs for all PHI access
  • Timestamp, user ID, action, resource logged
  • 7-year retention period

Β§164.312(e)(1) - Transmission Security

  • TLS 1.3 for all data transmission
  • HSTS enforcement

AWS BAA: Signed Business Associate Agreement with Amazon Web Services covering RDS, S3, and ECS.

Note: While our infrastructure is HIPAA-ready, full HIPAA compliance requires organizational policies and procedures. If you require a Business Associate Agreement (BAA) with Kura Center, please contact us.

SOC 2 Compliance Journey

Where We Are on SOC 2

βœ… Built

  • PostgreSQL RLS on 100+ tables
  • AES-256-GCM encryption at rest
  • TLS 1.3 in transit
  • Immutable audit logging
  • Multi-factor authentication (SMS and authenticator app)
  • AWS infrastructure with BAA

βœ… Readiness Work Complete

  • Controls mapped to the SOC 2 Trust Services Criteria
  • Evidence package compiled for auditor review
  • Data classification policy in place; remaining policy set in development through our readiness program

πŸ”„ In Progress Now

  • Selecting an independent audit firm for our SOC 2 Type I assessment
  • Type II observation period follows Type I

We don't publish target dates until an audit engagement is signed. When the report is issued, it will be available to customers under NDA.

Why We're Transparent: We believe in honest communication about our security posture. Rather than claiming certifications we don't yet have, we're showing you exactly where we are and where we're going.

Last reviewed: July 2026

Infrastructure & Operations

Cloud Infrastructure

  • Hosting: AWS (Amazon Web Services)
  • Region: us-west-2 (Oregon) - HIPAA-eligible region
  • Database: Amazon RDS PostgreSQL 15 with Multi-AZ
  • Compute: Amazon ECS Fargate (serverless containers)
  • Storage: Amazon S3 with versioning and encryption
  • CDN: CloudFront with AWS WAF

Availability & Disaster Recovery

  • Target Uptime: 99.9% (8.76 hours downtime/year)
  • RTO: 4 hours (Recovery Time Objective)
  • RPO: 5 minutes (Recovery Point Objective)
  • Backups: Automated daily snapshots, retained 30 days
  • Replication: Multi-AZ database with automatic failover

Access Control

  • RBAC: Role-based access control with granular permissions
  • MFA: Multi-factor authentication available (SMS, TOTP)
  • Session Management: Automatic 30-minute inactivity timeout
  • Password Policy: Minimum 12 characters, complexity requirements
  • Admin Access: All admin actions logged in audit trail

Security Testing

Current Security Practices

  • Automated dependency scanning (npm audit, Dependabot)
  • Static code analysis (ESLint security rules)
  • AWS Security Hub monitoring
  • CloudWatch alerting for anomalies

Independent Testing

  • Third-party penetration testing is scoped as part of our SOC 2 engagement, then annually thereafter
  • The SOC 2 Type I audit itself includes an independent assessment of our security controls

Questions About Security?

Our team is here to answer any security or compliance questions