Security & Trust

Security you can take to procurement

iqava handles regulated insurance data. Security and auditability are built into the platform, not bolted on — from granular access control to an immutable audit trail and self-hosting for the strictest requirements.

Granular access control

Role-based access with resource:action permissions and data scopes (own → global), plus authority limits and maker-checker patterns.

SSO & MFA

Microsoft Entra and Google single sign-on, domain routing, just-in-time provisioning, and TOTP multi-factor for local accounts. SSO can be enforced per domain.

Identity lifecycle

Directory sync from Entra (Graph) and Google (Admin SDK) with group-to-role mapping and automatic deprovisioning of removed users.

Immutable audit trail

Every privileged and data-changing action is recorded with actor, action, target and timestamp — exportable for your auditors.

Encryption

TLS in transit. Secrets such as directory credentials are encrypted at rest (AES-256-GCM); passwords are salted and hashed (scrypt).

Cloud or self-hosted

Run as multi-tenant SaaS or deploy inside your own environment (Docker / Kubernetes) for data residency and isolation requirements.

Multi-tenant isolation

Every record is tenant-scoped and enforced at the database with Postgres row-level security, so a query physically cannot return another tenant's data. Self-host single-tenant when isolation must be physical.

Operational integrity

Double-entry finance, reconciliation controls and licensing/entitlement checks keep the platform's financial and access state consistent.

Compliance roadmap

We align our controls with recognized frameworks (e.g. ISO 27001 / SOC 2 practices) and provide a Data Processing Agreement for enterprise customers. For a security questionnaire, penetration-test summary or our current posture, contact our team.