How we protect your data, who we share it with, and where we are on our compliance journey. Updated regularly — last reviewed July 25, 2026.
app.percelx.org, api.percelx.org, and related
subdomains. Excludes the marketing site and social profiles.
We build like a company that expects to be audited — because we do.
Every field we classify as Protected Health Information is individually encrypted at rest using industry-standard authenticated encryption with managed key rotation.
All traffic between browsers, our API, and our subprocessors is encrypted in transit. HSTS enabled.
Role-based access control. Organization admins never see individual assessment answers — only aggregated cohort insight.
Every admin action, data export, and access change is written to an immutable audit log.
Inbound webhooks from payment and integration partners are cryptographically verified and processed idempotently to prevent replay.
Per-IP and per-endpoint rate limits protect against brute-force and scraping.
Automated advisory checks on every deploy; critical CVEs block production merges.
Production data is fully isolated from non-production environments and never leaves controlled infrastructure.
PercelX runs on managed services from a Tier-1 US cloud provider with redundancy across availability zones. Static assets are delivered from a global CDN, application logic runs on hardened compute with process-level supervision, and customer data is stored in an encrypted managed database with strict network isolation and IP allow-listing. AI reasoning is performed inside our cloud provider's boundary under existing data-protection agreements — customer content is never sent to third-party model providers outside that boundary.
Detailed architecture diagrams and a full subprocessor inventory are available to enterprise prospects under NDA — contact security@percelx.org.
You own your data. We use it to serve you, not sell you.
Full details: Privacy Policy · Disclaimer.
Vendors that may process PercelX customer data on our behalf. We evaluate each for security posture and, where PHI is involved, require a Business Associate Agreement (BAA).
| Vendor | Purpose | Data | BAA | Region |
|---|---|---|---|---|
| Tier-1 US cloud provider | Application hosting, storage, content delivery, transactional email, and AI inference | PHI | Signed | United States |
| Managed database provider | Primary application data store | PHI | Signed | United States |
| Payments processor | Billing and subscription management | No PHI (billing PII only) | Not required | United States |
| Marketing email provider | Newsletter and event email — non-PHI only | No PHI | Scoped to non-PHI | United States |
| Internal productivity suite | Internal email and collaboration | No customer PHI | Enterprise agreement in place | United States |
| Scheduling provider | Consultation and demo scheduling | Contact info only | Not required | United States |
| Source-control & CI provider | Engineering source code and continuous integration | No customer data | Not required | United States |
Named vendors, versions, and regional deployment details are provided to enterprise prospects and customers under NDA as part of our Data Processing Addendum. Material changes to the underlying vendor list are communicated in advance to enterprise customers under contract. Request the full inventory or subscribe to change notifications at security@percelx.org.
Audit fieldwork is scheduled for Q4 2026 through an AICPA-registered CPA firm using a leading GRC platform for continuous control evidence. On completion we will make the report available under NDA on request.
PercelX operates as a business associate for customers whose use of the platform involves Protected Health Information. Technical safeguards required by HIPAA §164.312 are live today — access control, audit controls, integrity controls, transmission security, and encryption at rest for PHI fields. BAAs with our infrastructure subprocessors are in place. A BAA between PercelX and the covered entity is provided as part of an enterprise agreement.
Data-subject rights (access, correction, deletion, portability) are supported through our Privacy Policy contact.
Email security@percelx.org and we’ll respond within two business days.
Please report suspected vulnerabilities or incidents directly to security@percelx.org. We commit to:
Different questions go to different mailboxes so we can route quickly.