Security

How we protect your data

Vitalis Courier Service is built to carry protected health information, so security isn't optional. Here is exactly how we host, encrypt, back up, and control access to your data — and how to reach us if you find a problem.

Hosting & infrastructure

The platform runs on Microsoft Azure in US regions, on managed services with hardened baselines and a network perimeter that keeps tenant data off the public internet.

  • Azure Static Web Apps / Container Apps behind Azure Front Door
  • Private networking between the app tier and the tenant database
  • Infrastructure defined as code and change-controlled — no ad-hoc production edits
  • Secrets held in Azure Key Vault with soft-delete and purge protection; nothing hard-coded

Encryption in transit & at rest

Every byte is encrypted on the wire and on disk. The public tracking surface and all API traffic are HTTPS-only, and stored data is encrypted with platform-managed keys.

  • TLS 1.2+ enforced for all browser and API traffic; HSTS with preload
  • AES-256 encryption at rest for the database, blob storage, and backups
  • Strict Content-Security-Policy — the browser only ever talks to same-origin routes
  • The tenant API base and its credentials never reach the client

Access controls

Access is least-privilege, tenant-scoped, and audited. Operators only see the tenants they are assigned, and protected health information is masked by default.

  • Role-based access control on operator and client portals; tenant isolation enforced in the data layer
  • PHI shown minimum-necessary — identifiers masked at rest in the display surfaces and revealed only with a role and a logged reason
  • Public shipment tracking uses an opaque, single-purpose token — no login, no account enumeration, one shipment only
  • Admin mutations are written to an audit trail with actor, timestamp, and before/after diff

Backups & resilience

The platform is built so tenant data is continuously backed up and recoverable to a point in time, with a documented restore procedure that is drilled before launch — not assumed.

  • Point-in-time restore on the tenant database
  • Encrypted, geo-redundant backups retained per the data-retention policy
  • Documented recovery objectives: RTO ≤ 4 hours, RPO ≤ 1 hour (targets)
  • Restore procedure documented; drills run before service goes live

Incident response

The platform captures temperature excursions, custody gaps, and security events with a severity, an owner, and an escalation path. When service is active, affected clients are notified per their agreement — nothing is closed silently.

  • A defined severity ladder and on-call escalation for security and operational incidents
  • Client notification per contractual and regulatory obligations
  • Documented root-cause and corrective action before an incident is resolved
  • Security contact monitored: security@iqcloud.cloud

Compliance posture

The frameworks a compliance officer will ask about during vendor review.

HIPAA

Vitalis operates as a Business Associate; a BAA is executed before any protected health information is handled. PHI is handled minimum-necessary, masked by default, and access is role-gated and audited.

PCI-DSS

Payments, when enabled, are handled by Stripe. We never store full card numbers — cardholder data flows directly to the PCI-certified processor, keeping our environment out of scope.

GDPR / CCPA

We honor data-subject access and deletion requests, disclose our data use in the privacy policy, and retain personal data only as long as the custody record and our agreements require.

SOC 2 readiness

Controls across security, availability, and confidentiality are built to a SOC 2 posture. Ask us for our current attestation status during vendor review.

The clinical-handling controls (chain of custody, temperature, credentials) live on our Trust & Compliance page.

Responsible disclosure

Found a vulnerability? We want to hear from you. Email security@iqcloud.cloud with details and steps to reproduce. Please give us a reasonable window to remediate before public disclosure — we do not pursue good-faith researchers who follow this policy.

A PGP key for encrypted reports is available on request to security@iqcloud.cloud.

Questions from your security team? Talk to us

Bring us into your vendor review

We'll walk your security and compliance teams through our controls, share our BAA, and answer your questionnaire.