Security & Trust — AgudApp

AgudApp is built for sensitive health insurance operations. Security here is not only about passwords: it includes encryption, access controls, auditability, agency isolation, appropriate vendors, and contractual safeguards such as Business Associate Agreements (BAAs) when applicable. This page summarizes how the Platform is designed to support privacy, security and audit controls aligned with HIPAA — without absolute promises that no system can responsibly make.

1. PHI/PII-aware operations

The Platform handles Protected Health Information (PHI) and personally identifiable information (PII) as part of normal agency operations. Workflows, audit logs, permissions and data retention are designed around the principle of using the minimum necessary data and exposing it only to authorized users for legitimate operational purposes.

2. Encrypted sensitive data

Sensitive fields are encrypted at rest using AES-256-GCM with per-agency keys derived from a master key. Encrypted fields are revealed only when an authorized user explicitly requests it, and the action is recorded in the audit trail.

Data in transit is protected with TLS 1.2 or higher. Passwords are hashed with bcrypt and never stored in plaintext.

3. Per-agency isolation

Each agency operates within its own logically isolated database with separate encryption keys. The architecture is designed to reduce cross-agency exposure risk. Any attempt to bypass isolation is treated as a material breach of the Terms of Service.

4. Permissions and access control

Role-based access controls govern what each user can see and do. Multi-factor authentication (2FA) is available for every account and can be configured as mandatory by the Tenant Administrator. Access to sensitive fields requires an explicit action and is logged with the user, timestamp, IP address and request identifier.

5. Audit logs and traceability

Operational actions are connected to users, customers, applications, documents and timestamps. Audit logs are immutable — database triggers prevent updates or deletions. PHI access logs and electronically signed documents are retained for a minimum of six (6) years, in line with HIPAA retention requirements.

6. AI with human review

AgudApp uses AI to assist agents — for example, surfacing possible inconsistencies between uploaded documents and application data. The AI assists the agent; it does not make final decisions, does not approve or reject eligibility, and does not replace human review.

AI features are designed to operate within a BAA-supported vendor framework when PHI is processed, with per-tenant consent tracking, usage logging, per-user opt-in, access controls, data minimization where applicable, and continuous validation of model behavior. Every AI finding generates a task that an authorized user must review and resolve, with the resolution recorded in the audit trail.

AgudApp does not present AI as a black box. The framing of AI capabilities within this Platform is prudent: AI is a review and prioritization aid; final operational decisions remain under the agency’s workflow and licensed/professional review where applicable. AI vendor selection, BAA scope and PHI handling boundaries are subject to internal review and may be updated as the model landscape and partnerships evolve.

7. Infrastructure posture

The Platform is hosted on AWS infrastructure located in the United States, under a signed Business Associate Agreement (BAA). The infrastructure includes immutable audit logging, automated backups with documented retention, and a documented incident response plan. Backups are encrypted at rest.

8. Shared responsibility and contractual safeguards

Security for operations that handle PHI is not only about passwords or a single vendor commitment — it depends on a shared responsibility model between the Platform, the agency and its workforce.

On the Platform side, AgudApp provides technical controls (encryption, isolation, audit logs, role-based access) and contractual safeguards such as a Business Associate Agreement (BAA) with AWS for hosting infrastructure, and a BAA between AgudApp and each Tenant where applicable. A BAA is part of the contractual framework when vendors handle PHI; it does not, by itself, make any system “HIPAA compliant” in an absolute sense.

On the agency side, Tenants are responsible for the appropriate configuration of permissions and 2FA, the training and oversight of authorized users, the protection of credentials, the legitimate handling of data, and the operational practices required under applicable law.

Together — technical controls, contractual safeguards and responsible operational practice — form the security posture AgudApp is designed to support.

9. Designed to support HIPAA-aligned controls

The Platform is designed to support HIPAA-aligned privacy, security and audit controls. Compliance with HIPAA is a shared responsibility between AgudApp and each Tenant, governed by the Business Associate Agreement and described in Section 9 of our Terms of Service. AgudApp does not represent that any specific system or process is guaranteed to be compliant in every circumstance, because compliance depends on configuration, workforce training, operational practices and contextual factors under the Tenant’s control.

10. What this page is not

This page is not a security certification, an attestation, an audit report, a guarantee against breaches, or a substitute for the Business Associate Agreement and Terms of Service. For contractual security commitments, see the BAA and the Terms of Service.

11. Responsible disclosure and security contact

If you believe you have discovered a security vulnerability that affects the Platform, please report it to security@agudapp.com. We appreciate good-faith reports and will respond as quickly as practical. Please do not test on production data, do not exfiltrate data, and do not publicly disclose the issue before we have had a reasonable opportunity to investigate and remediate.

For privacy or data subject requests, contact privacy@agudapp.com. For contractual or BAA-related questions, contact legal@agudapp.com. For customer support, contact support@agudapp.com.

Version: v1.2  |  Last updated: May 28, 2026