How we protect your data
Vitalis Courier Service is built to carry protected health information, so security isn't optional. Here is exactly how we host, encrypt, back up, and control access to your data — and how to reach us if you find a problem.
Hosting & infrastructure
The platform runs on Microsoft Azure in US regions, on managed services with hardened baselines and a network perimeter that keeps tenant data off the public internet.
- Azure Static Web Apps / Container Apps behind Azure Front Door
- Private networking between the app tier and the tenant database
- Infrastructure defined as code and change-controlled — no ad-hoc production edits
- Secrets held in Azure Key Vault with soft-delete and purge protection; nothing hard-coded
Encryption in transit & at rest
Every byte is encrypted on the wire and on disk. The public tracking surface and all API traffic are HTTPS-only, and stored data is encrypted with platform-managed keys.
- TLS 1.2+ enforced for all browser and API traffic; HSTS with preload
- AES-256 encryption at rest for the database, blob storage, and backups
- Strict Content-Security-Policy — the browser only ever talks to same-origin routes
- The tenant API base and its credentials never reach the client
Access controls
Access is least-privilege, tenant-scoped, and audited. Operators only see the tenants they are assigned, and protected health information is masked by default.
- Role-based access control on operator and client portals; tenant isolation enforced in the data layer
- PHI shown minimum-necessary — identifiers masked at rest in the display surfaces and revealed only with a role and a logged reason
- Public shipment tracking uses an opaque, single-purpose token — no login, no account enumeration, one shipment only
- Admin mutations are written to an audit trail with actor, timestamp, and before/after diff
Backups & resilience
The platform is built so tenant data is continuously backed up and recoverable to a point in time, with a documented restore procedure that is drilled before launch — not assumed.
- Point-in-time restore on the tenant database
- Encrypted, geo-redundant backups retained per the data-retention policy
- Documented recovery objectives: RTO ≤ 4 hours, RPO ≤ 1 hour (targets)
- Restore procedure documented; drills run before service goes live
Incident response
The platform captures temperature excursions, custody gaps, and security events with a severity, an owner, and an escalation path. When service is active, affected clients are notified per their agreement — nothing is closed silently.
- A defined severity ladder and on-call escalation for security and operational incidents
- Client notification per contractual and regulatory obligations
- Documented root-cause and corrective action before an incident is resolved
- Security contact monitored: security@iqcloud.cloud
Compliance posture
The frameworks a compliance officer will ask about during vendor review.
HIPAA
Vitalis operates as a Business Associate; a BAA is executed before any protected health information is handled. PHI is handled minimum-necessary, masked by default, and access is role-gated and audited.
PCI-DSS
Payments, when enabled, are handled by Stripe. We never store full card numbers — cardholder data flows directly to the PCI-certified processor, keeping our environment out of scope.
GDPR / CCPA
We honor data-subject access and deletion requests, disclose our data use in the privacy policy, and retain personal data only as long as the custody record and our agreements require.
SOC 2 readiness
Controls across security, availability, and confidentiality are built to a SOC 2 posture. Ask us for our current attestation status during vendor review.
The clinical-handling controls (chain of custody, temperature, credentials) live on our Trust & Compliance page.
Responsible disclosure
Found a vulnerability? We want to hear from you. Email security@iqcloud.cloud with details and steps to reproduce. Please give us a reasonable window to remediate before public disclosure — we do not pursue good-faith researchers who follow this policy.
A PGP key for encrypted reports is available on request to security@iqcloud.cloud.
Questions from your security team? Talk to usBring us into your vendor review
We'll walk your security and compliance teams through our controls, share our BAA, and answer your questionnaire.