SOC 2 Type II
Certified Compliant
Your healthcare data deserves the highest level of protection. Learn how Affine keeps your PHI safe.
Certified Compliant
Fully Compliant
At Rest & In Transit
Security isn't an afterthought—it's built into every layer of our platform.
PHI never leaves your Snowflake environment. We deploy code to your infrastructure—your data stays where it belongs.
Every access request is verified. Role-based access controls ensure users only see what they need to see.
Every query, every access, every change is logged. Full visibility for compliance and forensics.
Multiple layers of security protect your data at every stage.
We maintain the certifications and practices required for healthcare data.
Annual audit of security, availability, and confidentiality controls.
Full compliance with healthcare privacy and security regulations.
Business Associate Agreements available for all customers.
Annual third-party penetration testing and remediation.
Your data is stored in your own Snowflake account, in the cloud region of your choice. Affine code is deployed to your environment—we never extract or store your PHI.
No, we never have access to your PHI. All data remains within your own Snowflake environment.
We follow a strict incident response protocol including immediate containment, root cause analysis, and customer notification within 24 hours.
Yes, our SOC 2 Type II report is available to customers and prospects under NDA. Please contact your account executive.