Skip to content
Tampa Dynamics

Security & trust

Built to be audited.

How we handle regulated data, what stands behind the work, and — because trust is built on candor — what we don’t claim.

The BAA chain, intact

If your data includes protected health information, every party that touches it needs a Business Associate Agreement — yours with us, and ours with anyone downstream. Ours is already signed: PHI workloads run on AWS HIPAA-eligible services under an active BAA. When you sign with us, the chain closes end to end.

Your organization

covered entity

signed BAA

Tampa Dynamics

business associate

signed BAA

AWS

HIPAA-eligible services

How we handle regulated data

Role-based access control

Access is scoped to the person and the job on every system we build. Nobody gets more than their role needs, including us.

Encryption in transit and at rest

Data is encrypted on the wire and on disk, with keys managed in the cloud provider's key-management service.

Audit logging

Who saw what, and when. Access and actions are logged so a compliance officer can answer an auditor without guessing.

De-identification at the boundary

Nothing containing PHI reaches a vendor that can't sign a BAA. Where a service sits outside the chain, data is de-identified before it gets there.

Tenant isolation at the data layer

A client matter or a patient record can never surface in someone else's query. Isolation is enforced where retrieval happens, and access rules live in the data layer itself.

What stands behind the work

  • The firm is insured. A certificate of insurance is available on request for your vendor file.
  • Real contracts. A standard MSA and statement of work, with a healthcare addendum for engagements that touch PHI.
  • You own what we build. Handover includes the code, the documentation, and the credentials. No lock-in by design.

This site runs the way we build

  • Analytics load only after you consent. Decline, and nothing loads at all.
  • Forms are rate-limited and validated server-side, and we collect the minimum the conversation needs.
  • Lucy, the chat assistant, runs server-side. Conversations are used to answer you and route your inquiry — they aren’t used to train models.

What we don’t claim

We don’t hold a SOC 2 report or an ISO 27001 certificate. We’re a small senior team, and we’d rather say that here than let a procurement checklist discover it later. What we do hold — an insured practice, a signed AWS BAA, and the delivery habits this page describes — is what lets the systems we build pass our clients’ audits.

If your vendor process requires an attestation we don’t hold, raise it on the first call. We’ll tell you honestly whether we can meet it.

Need the paperwork for a vendor review? Request documentation — or book fifteen minutes and bring your compliance officer along.