Security and Trust
Effective date: September 22, 2026
This page describes how Adaptive Flow Health approaches security, access control, and data responsibility for Adaptive Flow Studio. We aim to be straightforward about what we do and what we do not claim.
Account access and authentication
Access to Adaptive Flow Studio requires account creation and authentication. We use standard practices for account security, including credential verification.
You are responsible for:
- Keeping your login credentials confidential
- Not sharing your account with unauthorized users
- Using a strong, unique password
- Notifying Adaptive Flow Health promptly if you suspect unauthorized access to your account
Role-based access in shared workspaces
Adaptive Flow Studio includes role-based access controls that allow workspace administrators to manage user access, assign roles, and control what information users can view, edit, or export within the organization's shared workspaces.
Workspace administrators are responsible for managing user access appropriately, including removing users who no longer require access and ensuring role assignments reflect actual organizational need.
Data responsibility
You are responsible for the data you upload, paste, save, analyze, share, and export through Adaptive Flow Studio. Adaptive Flow Health does not review or validate the content of customer data for compliance with HIPAA or other privacy laws.
Protected Health Information may only be used in approved workspaces with the appropriate agreements (including a Business Associate Agreement where required) and safeguards in place. See our Data Use and HIPAA Notice for details.
Infrastructure and hosting
Adaptive Flow Studio is hosted on third-party cloud infrastructure selected for reasonable reliability and availability. We rely on reputable service providers for hosting, storage, and authentication.
We do not make specific claims about uptime guarantees, infrastructure redundancy, or disaster recovery beyond what is commercially reasonable for a SaaS product at our current stage.
Security practices
Adaptive Flow Health uses reasonable administrative, technical, and organizational measures to protect the platform. These include:
- Access controls limiting who can access platform systems and infrastructure
- Reasonable technical safeguards for data in transit and at rest
- Monitoring and review of platform access and operations
- Vendor selection with reasonable security considerations
We review and update security practices as the platform evolves.
What we do not claim
Adaptive Flow Health does not currently hold SOC 2 certification, HITRUST certification, FedRAMP authorization, or other third-party security or compliance certifications. We do not make specific claims about penetration testing cadence, vulnerability management timelines, or formal enterprise security programs beyond what is described on this page.
No system is completely secure. We make reasonable efforts to maintain platform security and will notify affected customers of material security events as required by applicable law or reasonable practice.
Contact us about security or BAA inquiries
If you believe you have discovered a security issue, please contact us before disclosing it publicly. We appreciate responsible disclosure.
For security concerns, Business Associate Agreement inquiries, questions about data handling, or governed organizational use:
Adaptive Flow Health LLC
1110 Lake Street #3
Venice, CA 90291
sjahnke@adaptiveflowhealth.com