ReMyll Trust Center

Security architecture and compliance frameworks.

Purpose-built software infrastructure engineered to safeguard compliance, intake, and governance records in regulated organizations.

One uncompromising security standard governs the entire ReMyll software suite. This Trust Center outlines our data protection posture, regulatory alignment, and responsible artificial intelligence principles.

01 · Security posture

Built for high-security regulated environments.

Security controls are implemented at the company level across all products, so protection is consistent across your entire organization. Our posture reflects a simple principle: strong controls reduce risk. We design for resilience, transparency, and responsible use.

Data encryption
All data is protected with industry-standard encryption in transit (TLS 1.3) and at rest (AES-256), with cryptographic key management separated from application layers.
Access control and identity
Enforced role-based access control with least-privilege defaults, single sign-on (SAML 2.0) support, and mandatory multi-factor authentication for administrative access.
Tenant isolation
Customer data is logically and cryptographically partitioned at the tenant level. Credentials valid for one tenant environment cannot reach or view adjacent tenant data.
Audit-grade event logging
System actions, user permissions, and record changes are captured in immutable, time-stamped logs available for internal compliance reviews and regulatory examinations.
Data lifecycle and retention
Configurable retention schedules hold records according to your institutional policies and permanently purge them upon contract termination or request.
Vendor and subprocessor oversight
Third-party subprocessors undergo security evaluations, enter into mandatory data protection agreements, and adhere to strict privacy standards.
02 · Statutory and regulatory alignment

Engineered around named statutory and governance standards.

ReMyll builds software workflows designed around the frameworks our customers work within across healthcare, financial services, public companies, federal contracting, higher education, and technology.

Data privacy and confidentiality
HIPAA and HITECH rules (Privacy, Security, and Breach Notification)
42 CFR Part 2 (Substance use disorder confidentiality rules)
State privacy statutes (CCPA/CPRA, Washington My Health My Data)
Program governance and reporting
HHS-OIG General Compliance Program Guidance
CMS Conditions of Participation and 42 CFR Part 483 (Requirements for long-term care facilities)
False Claims Act, 31 U.S.C. §3729 (Including deliberate ignorance and reckless disregard)
Sarbanes-Oxley §301 (Audit committee complaint procedures)
FAR 52.203-13 (Contractor code of business ethics)
Recordkeeping
Federal Rule of Evidence 803(6) (Business records exception)
Record retention and legal hold practices aligned to customer policy
Security and emerging artificial intelligence frameworks
HIPAA Security Rule safeguards (administrative, physical, and technical)
NIST AI Risk Management Framework and NIST SP 1270 (Bias in artificial intelligence)
Section 1557 of the Affordable Care Act (Nondiscrimination in health programs)
State artificial intelligence statutes (California SB 1120 and AB 3030, Colorado SB 26-189 effective January 1 2027, and New York City Local Law 144)
03 · Responsible artificial intelligence governance

The model proposes. The human decides.

Where artificial intelligence assists workflows anywhere in the suite, its role is strictly bounded, fully disclosed, and reviewable. No machine learning model makes autonomous determinations or final adjudications.

Bounded operational role
Artificial intelligence assists strictly with drafting, preliminary categorization, and risk scoring.
Human-in-the-loop adjudication
Every model-assisted action is logged alongside the human decision that follows it.
No model training on client data
Customer data is not used to train or tune models for other organizations.
Transparent and overridable
Model-assisted steps are clearly flagged, and outputs can be overridden by authorized leads.
04 · Product data isolation

Strict data separation by design.

While delivered as a cohesive software suite, ReMyll products run on independent backend environments to preserve reporter trust and institutional privacy.

Independent product stacks
Each application operates on its own dedicated infrastructure. There is no shared cross-product customer database.
Narrative isolation
Raw intake narratives, incident files, and reporter identities captured inside confidential reporting channels remain strictly isolated.
Blind metric synchronization
When products exchange data, the integration passes aggregate numeric counts only. Case narratives and personal details do not cross product boundaries.
Code-enforced boundaries
Data separation is hardcoded and verified by automated testing rather than relying on policy language alone.
05 · Security and procurement readiness

Vendor onboarding without the delay.

ReMyll is engineered around recognized security baselines covering confidentiality, integrity, and availability, allowing your team to complete vendor onboarding with speed and confidence.

Contractual data protections
Business associate agreements are executed with every covered-entity deployment, and data processing agreements are available for organizations outside HIPAA scope.
Security control alignment
Platform controls, access policies, and data handling workflows are built around confidentiality, integrity, and availability principles.
Direct security inquiries
For specific technical questions or procurement documentation, contact our privacy and security team directly.
06 · Our approach

Clarity over promises.

Our software strengthens governance. It gives your team structured assessments, scoring logic, and evidence management. It supports your internal processes and does not replace them.

Security controls enhance protection. Our commitment is to maintain a posture aligned with current best practices and to evolve it as threats and technologies change.

/01Responsible security postureOur controls reduce exposure and support enterprise governance. We continually review the threat landscape for change and improve our security posture.
/02Independent vendor evaluationWe provide the structure your team uses to evaluate third-party vendors. The assessment surfaces the evidence, and your team reaches the conclusion.
/03Framework alignmentOur controls are aligned with HIPAA and the NIST AI Risk Management Framework. Your compliance determination stays with your organization and its counsel.
/04Continuous improvementWe prioritize stability, transparency, and ongoing refinement, and we address issues as they are identified.
/05Your decisions, your authorityOur software evaluates, organizes, and surfaces information. Authorized individuals in your organization make decisions, and those decisions are recorded as theirs.
/06Your data stays yoursCustomer data is used only to deliver the service to your organization. Models are not trained or tuned on it, and it is not repurposed for any secondary use.