# Trust and compliance

We maintain a robust assurance program encompassing numerous platforms across industries. Our continuous monitoring program ensures we maintain our industry-leading secure framework as our customer base grows.

## HITRUST

![](https://images.ctfassets.net/cl3wt5ehhnlv/6sRVJC2IcKO7tvKELraYRL/a72ba125d37a98d33f44f64f059359ba/HITRUST-CSF-Certification.jpeg)

The HITRUST Cybersecurity Framework (CSF) evaluates against 19 domains of security covering a broad spectrum of administrative, physical, and technical controls. The HITRUST CSF encompasses all applicable HIPAA requirements as well as numerous best practices, structured in a maturity model to serve as a framework for higher levels of security. 

Redox is HITRUST certified. [See our certificates in our Trust Center]( https://trust.redoxengine.com).  

> **HITRUST certification date**
>
> HITRUST certifications are effective for two years, starting from the submission dates stamped on the report. We maintain compliance with HITRUST controls throughout this period and re-attest in time to ensure there's no gap in coverage.

## SOC 2

![](https://images.ctfassets.net/cl3wt5ehhnlv/5lOmr5urailYTy1C7Yh0X1/105d8374a2cf8616ea6a984c3fc6c803/soc2)

System and Organization Controls (SOC) 2 is an industry-standard, technology service provider report verifying compliance and controls pertaining to security and availability. Type 2 indicates that this is a multi-month, over-time evaluation period for compliance.

Redox has received a SOC 2® Type 2 report consistently since July 2017. [View our SOC 2 and SOC 3 reports in our Trust Center](https://trust.redoxengine.com/). 

> **SOC2 and SOC3 dates**
>
> SOC2 Type 2 and SOC3 reports represent an audit over a period of 6 to 18 months (Redox’s audit period is typically 12 months). The dates you see on the reports will be for that reporting window.
>
> Rest assured, we never have gaps in those audit windows, so you can always expect us to have a fresh report available within the coming year.

## GDPR

![](https://images.ctfassets.net/cl3wt5ehhnlv/6pumQuqirVd7O0fxGHeZ7h/427166aecd47b5432d3e23633a40a020/gdpr.png)

General Data Protection and Regulation (GDPR) is a European Union (EU) law on data protection and privacy in the EU and European Economic Area. It is a cornerstone of EU privacy and human rights laws. [Learn more about GDPR](https://gdpr-info.eu/).

Redox is GDPR compliant. [Refer to our privacy policy](https://www.redoxengine.com/legal/privacy-policy/) for details about our privacy procedures, including how to submit Data Subject Access Rights Requests (DSARs).

## CCPA and CRPA

![](https://images.ctfassets.net/cl3wt5ehhnlv/bAz8sRUkvEqCULgLt50sJ/f476f4de6278877633d02f9fb0f42408/ccpa-compliant.png)

[Learn more about the California Consumer Privacy Act of 2018](http://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?division=3.&part=4.&lawCode=CIV&title=1.81.5) (CCPA), which gives consumers more control over the personal information that businesses collect about them. Also, [read the CCPA regulations](https://govt.westlaw.com/calregs/Browse/Home/California/CaliforniaCodeofRegulations?guid=IEB210D8CA2114665A08AF8443F0245AD&originationContext=documenttoc&transitionType=Default&contextData=(sc.Default)) that provide guidance on how to implement the law. This works in conjunction with the California Privacy Rights Acts of 2020 (CRPA). [Learn more about the CPRA amendment](https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202120220AB1490).

Redox adheres to all applicable regulations surrounding the CCPA and CPRA. [See our CCPA disclosure](https://www.redoxengine.com/legal/ccpa-disclosures/).

## HIPAA

![](https://images.ctfassets.net/cl3wt5ehhnlv/328XSgogyiVhd5GskgSnoe/21f56b7e1c2a76b3dab1ef2ba2a2236b/hipaa-logo.jpg)

Per the U.S. Department of Health & Human Services website, HIPAA standards are as follows:

_To improve the efficiency and effectiveness of the healthcare system, the Health Insurance Portability and Accountability Act of 1996 (HIPAA), Public Law 104-191, included Administrative Simplification provisions that required HHS to adopt national standards for electronic healthcare transactions and codesets, unique health identifiers, and security._

[Read more about HIPAA](https://www.hhs.gov/hipaa/for-professionals/index.html).

Redox adheres to all applicable U.S. federal and state regulations, including HIPAA.

## NIST Cybersecurity Framework

![](https://images.ctfassets.net/cl3wt5ehhnlv/5AfZLHJ8bZyvKC011Dj1Ne/a9e0702989833d233f4f031b8bf01129/NIST_cybersecurity_framework)

National Institute of Standards and Technology (NIST) Cybersecurity Framework integrates industry standards and best practices to help organizations manage their cybersecurity risks. It provides a common language that allows staff at all levels within an organization—and at all points in a supply chain—to develop a shared understanding of their cybersecurity risks.

Redox works to align with these standards.
