HIPAA, NIST, SOC 2, and HITRUST for laboratory systems
How Salus's security model aligns with the frameworks public health programs are actually held to, and what it inherits from Snowflake.
Security as a foundation, not an add-on
Salus handles protected health information, so access is least-privilege, every action is audited, sensitive fields are encrypted, and every result carries a chain of custody that can be independently verified. None of that is optional configuration bolted on after launch.
What's inherited from Snowflake
Because all protected health information lives in Snowflake under a Business Associate Agreement, Salus inherits Snowflake's own certifications: FedRAMP, StateRAMP, SOC 1 and SOC 2 Type II, HITRUST CSF, and ISO 27001, alongside alignment with HIPAA, NIST, CLIA, CAP, and ISO 15189, the frameworks public health programs are actually evaluated against.
What Salus adds on top
Role-based access is scoped per lab, so permissions match each person's real responsibilities and are enforced on every mutating action, not just at login. Authentication uses scrypt password hashing and signed JWTs, with TOTP multi-factor authentication and SSO/SCIM provisioning available for organizations that need it.
Sensitive identifiers such as patient names and MRNs are encrypted at the field level, with blind-index search so encrypted data stays usable rather than forcing a tradeoff between security and searchability. Idle sessions log off automatically, a HIPAA technical safeguard that requires no staff discipline to enforce.
A chain of custody you can actually verify
Specimen events and released results are written to an append-only, cryptographically anchored ledger, so custody is tamper-evident end to end, a result's history can be verified without trusting any single database administrator. When an inspector asks who verified a result three months ago, the audit trail and custody record answer in seconds, not after a scramble through logs.
The same discipline extends to the AI layer: AI personas hold scoped permissions that mirror staff roles, only a human can fully disable a persona, and every persona control action is written to the same append-only audit trail as clinical actions.
See it in your laboratory's context.
Explore the live demo, no login and no request form.