Security Overview
A plain-language overview of current safeguards and shared responsibilities.
Current safeguards
- Unique accounts, role-based permissions, and multi-factor authentication controls.
- Encryption in transit using current industry-standard protocols.
- Restricted production access, audit logging, monitoring, and incident-response workflows.
- Environment separation, controlled changes, code review, and dependency checks.
- Backup and recovery controls appropriate to the service and record type.
- Provider-hosted card entry so PhiXenia does not intentionally store full card numbers or security codes.
Shared responsibility
Business customers remain responsible for their users and permissions, endpoint and network security, exported or locally copied records, configured data fields, retention choices, connected-provider credentials, and promptly removing access that is no longer authorized.
Reporting a concern
Report suspected unauthorized access or a vulnerability to security@phixenia.com. Do not include passwords, card numbers, security codes, Social Security numbers, or live customer data in the initial report. PhiXenia does not currently claim a third-party security certification on this page.