Security & Trust
Trust should be checkable.
Review how Graphium protects patient information, manages access, and monitors service availability. Our SOC 2 Type II report and supporting security documentation are available for your team’s review under appropriate confidentiality terms.
Protecting patient information
- Encryption. Patient information is encrypted at rest using AES-256 across databases, backups, object storage, and message queues. External connections use TLS 1.2 or higher, and internal application-to-database traffic is also encrypted.
- Authentication. Account protections include enforced password policies, account lockout, session management, and multi-factor authentication.
- Patient data stored in the cloud. Graphium’s iOS apps send field entries directly to the cloud and do not persist patient data to local storage on the device.
- Role-based access and audit trails. Permissions control access by user role. Audit trails record form access, field-level updates, and user authentication events. The apps support deployment through mobile device management.
- Integration client: outbound-only, no VPN required, and every HL7 message is purged from local memory the moment cloud receipt is confirmed.
- Breach history: none. No proven or suspected breaches in the company's history.
Availability and operations
- Service availability. Our enterprise agreements include a 99.95% availability commitment. Our public status page shows service availability, incident updates, and scheduled maintenance by component.
- Operations: Continuous monitoring and 24/7 on-call engineering coverage for production incidents.
- Continuity and recovery. Disaster recovery and business continuity documentation is available under contract for your team’s review.
- U.S. operations: Customer service, engineering, and patient data storage are based in the United States.
- Stability: Physician-owned and profitable, with 15 years focused on anesthesia software.

Independent review and documentation
- SOC 2 Type II: clean opinion, no exceptions noted. Report available under NDA.
- HIPAA: Business associate agreements are standard.
