Security & compliance

Protection you can hand to your compliance officer.

Zentake is 100% HIPAA compliant, with a signed BAA on every plan. Security here isn't a feature, it's the foundation the platform is built on.

Signed BAA

Included on every plan

HIPAA compliant

100% compliant by design

AES-256 & TLS 1.2

Encrypted at rest and in transit

MFA & audit logs

Every access event tracked

HIPAA Compliance

Zentake maintains compliance with HIPAA, the federal law governing protection of personal health information (PHI) and electronic personal health information (ePHI). The platform has undergone third-party audit validation, meeting or exceeding all required safeguards.

E-Signature Compliance

The service complies with:

  • Electronic Signatures in the Global and National Commerce Act (ESIGN Act of 2000)
  • Uniform Electronic Transactions Act (UETA of 1999)

Security

Key security measures include:

  • Transport Layer Security (TLS) Version 1.2 encryption for connections
  • AES-256 encryption standard for stored data
  • Regular server updates and security validation
  • Intrusion detection system monitoring network connections
  • AWS data center infrastructure with ISO 27001, ISO 27017, ISO 27018, SOC 2, and HIPAA certifications

Data Protection

Zentake restricts data access through:

  • Employee background checks and security training
  • Limited access based on job necessity
  • Comprehensive access logging and monitoring
  • Regular account and permission reviews
  • High-availability servers with encryption in transit and at rest

System Reliability

The platform operates on AWS services across multiple availability zones, ensuring continuous operation. A disaster recovery plan and business continuity plan guide operational resilience.