HIPAA · AES-256 · PHI SECURED

PHI secured. HIPAA compliant.

Security is not bolted on at the end — it is how Zeus is built. Your patient data stays encrypted and isolated inside our private environment, end to end.

AES-256Encrypted at rest
TLS 1.2+Encrypted in transit
7-yearImmutable audit log
0PHI to third parties
// VPC BOUNDARY
PRIVATE CLOUD · ISOLATED NETWORK PHI · AES-256 AT REST Encrypted record · ***8741 Encrypted record · ***2319 AI · PRIVATE ENDPOINT LLM inference No PHI to third parties
Encryption & isolation

Encrypted at rest. Encrypted in transit.

AI runs through a private endpoint inside our network. No PHI goes to third parties. Ever.

  • AES-256 at rest — every record encrypted in the database and in object storage.
  • TLS 1.2+ in transit — enforced on every request, inside and at the edge.
  • Private by design — PHI stays inside our private, isolated network and never leaves it.
  • Role-based access · 11 roles — enforced on every request at the backend, with sensitive fields like SSN and DOB masked by role.
  • Immutable audit log — every PHI access, append-only, 7-year retention · 15-min session timeout.
Defense in depth

Eight layers around your data.

01

Encrypted, end to end

AES-256 on every record at rest and TLS 1.2+ on every request in transit. Unencrypted database connections are rejected outright, not just discouraged.

02

Isolated in a private network

PHI lives inside a private, isolated network and never leaves it. There is no public path to the database or file storage, and every service that touches patient data runs inside the same boundary.

03

Every client, separated

Each client gets its own isolated database schema — separated at the schema level, not just filtered by a column — with row-level security and application-level checks layered on top.

04

AI without exposure

LLM inference runs through a private endpoint inside our own environment. The model works on your data without any PHI going to third-party providers.

05

Least-privilege access

Role-based access across 11 roles, enforced at the backend on every request — not just in the UI — with a 15-minute session timeout.

06

PHI masked by role

Sensitive fields — social security number, date of birth, insurance details — are masked based on role, so users only ever see the fields their job requires.

07

Tamper-evident auditing

Every PHI access is written to an append-only audit log with 7-year retention, so there is always a complete record of who saw what and when.

08

Contracts that back it up

HIPAA compliant, with a signed Business Associate Agreement in place before any PHI changes hands.

Questions, answered

Security, answered.

What security and compliance teams ask before trusting Zeus with PHI.

PHI stays inside our private, isolated environment and never leaves it. Records are encrypted at rest with AES-256, and every service that touches PHI runs inside that same boundary. There is no copy of your data sitting anywhere else.

View all FAQs

Need the full security detail?

We will walk your team through the architecture, the controls, and our BAA — and answer anything your security review needs.

Talk to our team