top of page

InsightAlly Security and Compliance Overview 

Purpose

This memorandum provides a summary of the security, privacy, and regulatory compliance posture of InsightAlly for prospective customers, partners, and diligence reviewers.  

Regulatory and Compliance Alignment  

HIPAA

InsightAlly is architected to comply with the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. The platform supports use by covered entities and business associates through documented administrative, physical, and technical safeguards, including role-based access controls, least-privilege enforcement, audit logging, and in-boundary handling of protected health information.

SOC 2

InsightAlly’s information security program is aligned with the AICPA Trust Services Criteria. InsightAlly has successfully completed a SOC 2 Type 1 audit. SOC 2 Type 2 controls are in operation and the corresponding audit is in progress..

HECVAT

InsightAlly aligns with the Higher Education Community Vendor Assessment Toolkit and is completing formal HECVAT documentation. Responses are supported by documented control evidence.

Infrastructure and Hosting

InsightAlly runs on Amazon Web Services using HIPAA eligible services. Data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit. Access follows least privilege: role based controls, logged administrative activity, and environment separation between production and development. SOC 2 Type 1 is complete. Type 2 observation is in progress. Business Associate Agreements are available for covered entities and their partners. Security here is not a feature list. It is the operating baseline every Ally inherits.

AI and AWS Bedrock Architecture  

All model inference runs through AWS Bedrock inside our AWS security boundary. Protected health information is never routed to external model providers, and customer data is never used to train models. Every AI output is traceable to its source documents, and workflows that carry clinical, financial, or compliance consequences require human review before action. That is deliberate. AI does not fail quietly. It fails at scale. Our architecture assumes it, which is why governance is built into the pipeline, not bolted on after.

AI and AWS Bedrock Architecture  

InsightAlly uses AWS Bedrock as its managed foundation model layer. AWS Bedrock foundation models are pre-trained, and AWS does not use customer inputs or outputs to train its base models.  

 

Any model fine-tuning involving protected health information occurs solely within a BAA-covered AWS environment using HIPAA-eligible configurations. InsightAlly does not permit training or fine-tuning with PHI outside such environments.  

 

Logging and monitoring services are configured within HIPAA-compliant boundaries. Access logs and workflow logs are protected, retained under policy, and reviewed for audit and incident response purposes.  

 

Only foundation models supported under AWS HIPAA-eligible services are used for PHI workloads. InsightAlly does not route PHI to external third-party model infrastructure outside AWS Bedrock.  

Data Protection and Encryption  

All data at rest is encrypted using AES-256. Data in transit is encrypted using TLS 1.2 or higher. Encryption keys are centrally managed with role-based access and rotation policies.  

Access Controls and Governance

InsightAlly enforces role-based access controls aligned to user personas, multi-factor authentication for administrative access, segregation of duties, and auditable workflow execution.  

 

The platform operates as a governed support layer and does not modify or override customer systems of record.  

Incident Response and Third-Party Risk  

InsightAlly maintains a documented incident response plan with defined escalation, notification, and remediation procedures. Vendor and service providers are reviewed under a third-party risk management process.  

 

Customer data is not resold, reused, or used for generalized AI model training.

insightally-security-architecture_1.png
bottom of page