Security & Compliance

HIPAA-compliant infrastructure, encryption, access controls, and audit trails.

🔒 HIPAA Compliant

Taliswitch is fully HIPAA-compliant with technical, administrative, and physical safeguards. We sign Business Associate Agreements (BAAs) with all customers.

HIPAA Compliance

Technical Safeguards

  • TLS 1.3 encryption in transit
  • AES-256 encryption at rest
  • Two-factor authentication (2FA)
  • Automatic session timeouts
  • IP allowlisting available

Administrative Safeguards

  • BAA with all customers
  • Security training for all staff
  • Incident response plan
  • Regular risk assessments
  • Vendor management program

Physical Safeguards

  • SOC 2 Type II certified data centers
  • 24/7 physical security
  • Biometric access controls
  • Video surveillance
  • Disaster recovery procedures

Audit Controls

  • Complete audit logs for all PHI access
  • User activity tracking
  • Login/logout tracking
  • Export audit reports
  • Retention: 7 years minimum

Data Encryption

In Transit

All data transmitted between users and Taliswitch servers uses TLS 1.3 encryption:

At Rest

All PHI stored in Taliswitch databases is encrypted using AES-256:

Access Controls

Invite-Only Access

Taliswitch does not allow self-registration. All users must be invited by an organization administrator:

Role-Based Permissions

Access is controlled by user roles:

Multi-Tenant Isolation

Every customer has a separate, isolated environment:

Audit Trails

Every action in Taliswitch is logged for compliance:

What We Log

Accessing Audit Logs

For Admins: Settings → Audit Logs → Export

For Compliance: Contact security@dexzyle.com for formal audit reports

Retention: Logs retained for 7 years minimum (configurable up to 10 years)

Data Residency

Taliswitch data is hosted in SOC 2 Type II certified data centers:

Disaster Recovery & Backups

Backup Schedule

Recovery Time Objectives (RTO)

Testing

Disaster recovery procedures tested quarterly. Last test: November 2025 (successful).

Security Incident Response

In the event of a security incident:

  1. Detection: 24/7 monitoring with automated alerts
  2. Containment: Immediate isolation of affected systems
  3. Investigation: Root cause analysis within 24 hours
  4. Notification: Customers notified within 72 hours if PHI is affected
  5. Remediation: Fixes deployed and documented
  6. Review: Post-mortem and process improvements

Report a Security Issue: security@dexzyle.com (monitored 24/7)

Penetration Testing & Audits

Certifications & Compliance

Customer Responsibilities

While Taliswitch provides the secure platform, customers must:

Security Contact

Questions about security or compliance?