Security &Compliance
At HORUSOFTACEAE, security and personal data protection are not afterthoughts. They are designed into every layer of our systems — from architecture and access control to AI workflows, audit trails, encryption, and data governance.
Our Commitment
Information Security Management System
At Horusoftaceae, security is not a feature — it is the foundation of every system we build. Our Information Security Management System (ISMS) has been audited and certified to the international standard ISO/IEC 27001:2022.
We commit to protecting the integrity of our clients' enterprise data, our pharmaceutical partners' confidential trial information, and the protected health information of every patient whose data flows through our platforms.
This certification is not a badge we earned once — it is a discipline we practice every day. Continuous monitoring, regular penetration testing, and annual recertification audits ensure our controls remain effective against an evolving threat landscape.
Standards
Compliance Frameworks
Our platforms are engineered to align with three of the most critical regulatory frameworks in healthcare and life sciences.
- ISMS foundation with annual third-party audits
- Risk management framework for data assets
- Access control and security monitoring
- Supplier & third-party security governance
- Continuous improvement
- Immutable, tamper-proof audit trails
- Electronic signature support with user authentication
- Record integrity controls
- Validation documentation support
- Audit trail review & reporting
- Protected Health Information (PHI) safeguards
- AI-assisted PHI masking — de-identification before storage
- Role-based access and encryption
- Audit logging and data minimization
- Breach response workflow support
Architecture
Data Protection Infrastructure
Every platform we ship is built on a zero-trust, defense-in-depth architecture that protects data at every layer — from application logic to physical storage.
Dynamic datasource routing creates complete data isolation between tenants. Your data is processed and stored in a dedicated schema — cross-tenant leakage is architecturally impossible.
In transit: TLS 1.3 on all connections. At rest: AES-256 encryption for stored data — with role-based and least-privilege access.
Protected Health Information is automatically detected and de-identified before storage using AI-assisted masking aligned with the HIPAA Safe Harbor method.
Every read, write, and modification of sensitive data is logged in real time. Logs are write-once and tamper-proof — supporting personal data processing logs and compliance reviews.
PDPL Readiness — Law No. 91/2025/QH15
Vietnam's Personal Data Protection Law establishes a comprehensive framework for protecting personal data. HORUSOFTACEAE designs systems with privacy-by-design and data-protection-by-design principles to help organizations prepare for and operationalize personal data protection requirements — from consent and data subject rights to processing logs, breach response workflows, and cross-border transfer governance.
Review Our Security Documentation
We provide detailed compliance documentation and architecture diagrams to qualified enterprise partners under NDA.
Request Solution Survey