# Security & Compliance Matrix

For your IT security review. This mirrors the live detail on
[salusagentic.com/technology](https://salusagentic.com/technology).

## Platform controls (Salus)

- Role-based access control, scoped per laboratory
- Comprehensive audit trails on every mutating action
- Encryption in transit and at rest
- Real authentication: password + scrypt hashing, signed JWTs, TOTP MFA, SSO/SCIM
- Field-level encryption for sensitive identifiers (blind-index search)
- Verifiable, cryptographically anchored chain of custody
- Automatic session logoff (HIPAA technical safeguard)
- Cloud resiliency and backup

## Public-health standards Salus supports and aligns with directly

- HIPAA
- NIST Cybersecurity Framework
- NIST SP 800-53
- CLIA
- CAP
- ISO 15189

## Inherited from Snowflake, under a signed Business Associate Agreement

All protected health information in Salus resides in Snowflake. Under a
signed BAA, Salus inherits the certifications and authorizations Snowflake
maintains for the infrastructure layer:

- FedRAMP (Moderate and High)
- StateRAMP / GovRAMP
- SOC 1 Type II
- SOC 2 Type II
- HITRUST CSF
- NIST SP 800-171
- ISO/IEC 27001
- ISO/IEC 27017
- ISO/IEC 27018 (PII Protection)
- PCI DSS
- IRAP
- HIPAA / HITECH (BAA)
- GxP

**Note:** CLIA is intentionally not listed as a Snowflake-inherited
certification -- CLIA certifies laboratories, not infrastructure providers.
Salus's own CLIA alignment is listed above under "public-health standards."

Sources verified against docs.snowflake.com/en/user-guide/intro-compliance
and trust.snowflake.com.

---

*Provided by Salus Agentic as reference material. Confirm current
certification status directly with Snowflake's Trust Center for anything
your security review treats as load-bearing.*
