AltraSync Trust Center

Security

Last updated: June 24, 2026. AltraSync uses layered administrative, technical, and operational controls to protect company workflows and sensitive uploaded documents.

Access controls

Users access AltraSync through authenticated accounts. Permissions are managed by role and company. Super Admin controls global settings, company users are isolated by tenant/company, and regular users only see the areas granted to them.

Login protection

  • Mandatory recovery email setup for user accounts.
  • Email two-factor verification where configured.
  • Failed-login lockout and session timeout controls.
  • Optional single-login enforcement to replace older sessions.

Data location

Azure production uses a persistent data root under /home/aba_audit_data. Code is deployed from GitHub, while database files, uploads, support attachments, logs, and backups stay in the Azure persistent data area.

Retention safety

Retention cleanup is designed to remove expired PHI-heavy document/evidence files while keeping safer operational history such as status, logs, and counts. Cleanup should never delete users, companies, settings, or audit history.

AI safety

AI features are admin-controlled. Dashboard trend summaries use aggregate company counts only and do not show token usage to normal dashboard users. Token logs are restricted to Super Admin AI Settings.

Support safety

Support tickets include request metadata to help Super Admin resolve issues. Users are reminded not to paste or attach PHI unless necessary and approved.

Incident handling

Suspected security or privacy incidents should be reported promptly through Support or to support@altrasync.com. AltraSync support should preserve relevant logs and coordinate with affected customers for review.

Official resources

For general healthcare security background, users can review HHS resources for the HIPAA Security Rule and HIPAA Privacy Rule.

Important: This page summarizes AltraSync platform controls. It does not replace a customer's own security risk analysis, HIPAA policies, workforce training, contracts, Business Associate Agreement review, or legal compliance program.