Enterprise-grade security built for California care facilities
Built with the security features required to protect resident health information
Internal readiness work complete β now selecting an independent audit firm for our Type I assessment
Your data is encrypted the same way banks protect financial information
Security explained in plain English
Think of Kura Center like a building with separate locked filing cabinets for each facility. Your facility's cabinet has its own unique key. Even if someone broke into the building, they couldn't open your cabinet without your specific key. That's how we keep your data completely separate from other facilities.
Imagine a security camera that records everything, but the recordings are locked in a safe that can't be opened or erased. That's our audit trail. Every time someone views a resident's record, documents a service, or makes a change, it's permanently recorded with the date, time, and who did it. Perfect for inspections.
Encryption is like putting your data in a safe. Even if someone stole your computer or intercepted your internet connection, all they'd see is scrambled gibberish. We use the same encryption that banks use to protect financial information.
Not everyone needs access to everything. Administrators see everything, managers see schedules and reports, and staff see their own schedules and the residents they work with. Just like you wouldn't give every employee the keys to every room in your facility.
When licensing or DDS shows up, you can pull complete, unalterable records in minutes. No scrambling for paper files.
Residents and families can trust that their information is secure and only seen by authorized staff.
Your data is more secure in Kura Center than in filing cabinets or spreadsheets on staff computers.
Complete audit trails and EVV compliance built-inβexactly what DDS requires for QIP.
Know that your facility's data is protected by the same security standards used by hospitals and banks.
All this security happens automatically. Staff just do their jobsβthe system handles the security.
Your data is safe. It's stored in secure data centers, not on your computer. You can log in from any device and your data is still there. Just change your password and the thief can't access anything.
We have multiple layers of protection. Even if someone broke through one layer, your facility's data is isolated and encrypted. They'd need your specific encryption keys to read anythingβand those are stored separately and securely.
No. Records are permanent and cannot be deleted or altered. If someone makes a correction, both the original and the correction are saved with timestamps. This protects you during inspections.
Kura Center is built HIPAA-ready, and everything runs on infrastructure covered by a signed Business Associate Agreement with AWS. If your facility requires a BAA with Kura Center, contact us β we'll work through it with you.
You own your data. You can export everything at any time in standard formats. No vendor lock-in, no hassles.
The answers your IT reviewer or Regional Center will ask for β at a glance
| Hosting | AWS (us-west-2), signed Business Associate Agreement in place |
| Encryption | AES-256 at rest, TLS 1.3 in transit |
| Tenant isolation | Enforced at the database layer (PostgreSQL Row Level Security) |
| Access control | Role-based permissions, MFA (SMS or authenticator app), automatic session timeout |
| Audit trail | Append-only, tamper-proof, retained 7 years (Title 22) |
| Backups & recovery | Automated daily backups, multi-zone failover, 4-hour recovery objective |
| HIPAA | HIPAA-ready architecture aligned to the Security Rule's technical safeguards |
| SOC 2 | Readiness complete; independent Type I audit firm selection underway |
Completing a security questionnaire or vendor review? Contact us β we'll fill it out with you.
Standard: PostgreSQL Row Level Security (RLS), enforced on every table holding facility data (100+)
Each facility's records are isolated by the database itself, not just by application code. Every query is automatically restricted to the requesting facility, so even an application-level vulnerability cannot expose one facility's data to another.
At Rest: AES-256-GCM
In Transit: TLS 1.3
Implementation: Append-only audit log
Every create, read, update, and delete operation is logged with the acting user, facility, action, affected record, change details, IP address, and timestamp. The application's database role is denied UPDATE and DELETE on the log table, so audit records cannot be altered or removed β corrections are recorded as new entries alongside the original. Logs are retained for 7 years per California Title 22 requirements.
Kura Center is built with HIPAA-ready infrastructure and implements technical safeguards required by HIPAA Security Rule.
AWS BAA: Signed Business Associate Agreement with Amazon Web Services covering RDS, S3, and ECS.
Note: While our infrastructure is HIPAA-ready, full HIPAA compliance requires organizational policies and procedures. If you require a Business Associate Agreement (BAA) with Kura Center, please contact us.
We don't publish target dates until an audit engagement is signed. When the report is issued, it will be available to customers under NDA.
Why We're Transparent: We believe in honest communication about our security posture. Rather than claiming certifications we don't yet have, we're showing you exactly where we are and where we're going.
Last reviewed: July 2026
Our team is here to answer any security or compliance questions