# Wellthy _Trust Center_

Wellthy is dedicated to maintaining the highest standards of security and compliance, ensuring that our members (and their data) are protected at every step. By integrating these principles into everything we do, we uphold our mission of simplifying care for families, fostering trust, and providing a safe and reliable environment for navigating the complexity of care.

## Secure data hosting

Wellthy’s data and web services are hosted on the AWS cloud platform, leveraging its robust infrastructure and compliance with industry standards like ISO 27001 and SOC 2. Data is backed up regularly at alternative sites and offline locations.

## Encryption

Data shared with Wellthy by members is encrypted at-rest via AES-256 and in-transit via TLS 1.2 or higher. We also utilize a dedicated SSH File Transfer Protocol (SFTP) site that supports Pretty Good Privacy (PGP) encryption when accepting client eligibility files.

## Authentication and access controls

Wellthy uses Auth0 for secure authentication. We have robust password requirements and follow authentication guidelines and best practices as described in NIST 800-63. We also employ strong access controls, including multi-factor authentication, role-based access, and least-privilege principles.

## SOC 2 Type II compliance

For five years, Wellthy has successfully held and maintained a SOC2 Type II compliance certification, demonstrating our commitment to the highest standards of security, availability, and confidentiality.

## Penetration testing

Wellthy performs extensive external and internal penetration testing with an accredited third-party at least once per year and after any significant infrastructure or application upgrade or modification.

## Secure software development

Wellthy ensures secure software development through rigorous code reviews, extensive testing, agile practices, and continuous integration, prioritizing security and reliability in every release. Our development process includes comprehensive threat modeling to proactively identify and mitigate potential vulnerabilities early in the design phase.

## TRUSTED BY THE WORLD'S LEADING COMPANIES

## Learn more about _our commitment_ to security and compliance

### SOC 2 Type II compliance

Access detailed security and compliance information.

### FAQs

**How does Wellthy protect my personal and sensitive information?**

Member data shared with Wellthy by members is encrypted at-rest via AES-256 and in-transit via TLS 1.2 or higher.

**Is Wellthy compliant with privacy regulations like GDPR?**

Wellthy manages personal information in accordance with GDPR, including how information is collected, processed, and disclosed.

**Is Wellthy compliant with HIPAA?**

Wellthy builds its products, programs, and culture around the foundations of HIPAA.

**Does Wellthy conduct annual risk assessments?**

Yes. On an annual basis, a formal, written IT / Security risk assessment is conducted based on relevant frameworks, advisories, or regulatory requirements. Our annual security risk assessment typically follows the National Institute of Standard and Technology (NIST), International Organization for Standardization (ISO), or Health Insurance Portability & Accountability Act (HIPAA) framework to ensure we are reviewing our security posture across the most relevant frameworks.

**Does Wellthy conduct annual penetration tests?**

Yes. Wellthy performs external and internal penetration testing with an accredited third-party at least once per year and after any significant infrastructure or application upgrade or modification.

**Does Wellthy have an incident response plan?**

Yes. Our incident response program includes a step-by-step playbook for how to escalate, respond, and recover to platform, security, and privacy incidents.

**Does Wellthy have logging and monitoring in place?**

Yes. Wellthy has a variety of tools in place that log and monitor actions on our website, platform, and devices. Automated tools provide real-time monitoring and notification of suspected wrongdoing and vulnerability exploitation.

## Reporting a security issue

If you are a security expert or researcher, please send details of the issue to security@wellthy.com. We take security seriously and are committed to supporting responsible disclosure of any issues you may uncover.

The scope of this program applies to the following systems and services:

- https://wellthy.com  
- https://app.wellthy.com  
- https://community.wellthy.com

The following are prohibited and will not be considered in scope for our program:

- Do not attempt to conduct post-exploitation, including modification or destruction of data.
- Do not attempt to access or modify another user’s account or data.
- Do not attempt to target Wellthy employees or its customers, including social engineering attacks, phishing attacks or physical attacks.
- Do not perform physical attacks against any Wellthy facility.
