Is this your company?Buyers are checking Awell Health here. Claim awellhealth.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Awell is a low-code platform used by clinical and product teams to design clinical workflows and integrate them into their tech stack. With Awell, care organizations automate routine clinical tasks, synchronize data between systems and drive seamless coordination between care teams and patients. Awell’s customers have improved the lives of hundreds of thousands of patients across a wide array of medical conditions. They achieved results such as a 50% increase in care team capacity, a 40% reduction in length of stay, and a 25% reduction in emergency room admissions. This report is a live dashbo
SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Awell Health SOC 2 compliant?
Awell Health is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Awell Health ISO 27001 certified?
According to Awell Health's public trust center, Awell Health is ISO 27001 certified. On SOC2C this listing is Listed.
Is Awell Health GDPR compliant?
According to Awell Health's public trust center, Awell Health is GDPR compliant. On SOC2C this listing is Listed.
Is Awell Health HIPAA compliant?
According to Awell Health's public trust center, Awell Health is HIPAA compliant. On SOC2C this listing is Listed.
Is Awell Health SOC 2 Type I or Type II?
Awell Health is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Awell Health's SOC 2 for a vendor risk assessment?
Yes. Awell Health's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Awell Health penetration tested?
Awell Health hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Does Awell Health have an ISO 27001 certificate?
Awell Health publishes an ISO certificate on its trust center; you can request access through SOC2C.
Can I get Awell Health's SOC 2 report?
Awell Health's SOC 2 report is available on request. Request access through SOC2C and we coordinate the company-side NDA and delivery.
Is Awell Health secure?
Security isn't a single yes/no, but Awell Health is SOC 2 Type II compliant and holds ISO 27001, GDPR, HIPAA, SOC 2 Type II. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Awell Health have a bug bounty or vulnerability disclosure program?
Awell Health hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@awellhealth.com or via a /security page (Awell Health lists a security contact).
Who are Awell Health's subprocessors?
Awell Health lists 5 subprocessors on its trust center, including Google Cloud Platform, Stytch, Mailgun, Openai, TactionSoft. Buyers use this for fourth-party risk review.
Where does Awell Health host or store data?
Awell Health hosts on GCP, and handles Customer personally identifiable information, Personal health information. Data residency details are on its trust center.
Where is Awell Health's trust center or security page?
Awell Health's trust center is at https://security.awellhealth.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Where is my data hosted with Awell?
Our deployments are fully regional, so your data can be securely hosted either in Europe, UK or the USA via Google Cloud Platform to meet your compliance needs. This means that by design, the data never leaves the region.
Are you SOC 2 certified?
Yes! Awell has been SOC2 certified since December '24. We've had no exceptions to any of our controls. Feel free to download our report here in the trust center for your own third party risk assessments! Note that we also only work with reputable vendors and third parties that have ISO27001:2022 and/or SOC2 compliance.
Are you covered by NIS2?
Yes, we're considered as an "important" service provider under NIS2 and applied/subscribed to the relevant authorities to meet the requirements. NIS2 is a EU regulation focusing on standardising a level of cyber security controls in important and essential industries.
Do you encrypt data?
Data is encrypted at rest (AES 256) and in transit (HTTPS over TLS1.2+). Our database is deployed on a kubernetes cluster in the Google Kubernetes Engine. It is backed by a kubernetes persistent volume, which is covered by Google Cloud’s Default encryption of data at rest. In cluster db connections use the HTTPS channel and therefore benefit from encryption in transit through TLS. HTTP access to the database is disabled to prevent connections without encryption in transit.
How scalable is Awell?
Our product is deployed on Google Kubernetes Engine, and we use regional clusters which already come with built in redundancy (3 zones per region). We have daily backups in all environments, and the provisioning of new environments is fully automated (IaC) so in the worst case scenario where a google data center is fully down we can create a new deployment in a different datacenter and be up and running with the latest backup in a day at most, but realistically it can be as quick as one hour. Our integrations and infrastructure are designed to handle large volumes of patients. Have a look at our system status page for more information.
Are you HIPAA and/or GDPR compliant?
Yes, the Awell platform is both HIPAA and GDPR compliant via Vanta.
Is Awell's security tested?
Yes, 100%! We are continuously striving to improve our security posture. While we have our own internal programs, we also have external audits & tests to challenge ourselves and prove our customers we are to be trusted! A quick glance at our testing: 1. Yearly internal ISO27001 audit (performed by an external expert) 2. Yearly external ISO27001:2022 audit 3. Yearly penetration tests 4. Public bug bounty program (responsible disclosure)
How do you support multiple environments? Like Development/Test/Production?
We currently offer access to two environments: Sandbox and Production. We have internal-facing environments to support the software development lifecycle. We are able to flexibly support your ongoing integration and testing needs, so please feel free to discuss them with you.
How often are pen tests & audits performed?
Penetration tests are scheduled every year and performed by an external party.
What do we have in place for disaster recovery?
Our product is deployed on Google Kubernetes Engine, and we use regional clusters which already come with built-in redundancy (3 zones per region). Adding another layer of redundancy (replicate the US deployment to different data centres for example) is on the technical roadmap but not available yet. We have daily backups in all environments, and the provisioning of new environments is fully automated, so in the worst case scenario where a Google data centre is fully down we can create a new deployment in a different datacenter and be up and running with the latest backup in a day max (as defined in our ISMS disaster recovery policy), but realistically it can be as quick as one hour.
Do you require multi-factor authentication on all enterprise applications and production systems?
Yes! We use Google as our IDP and only allow phishing-proof MFA options. We are using Passkeys are the next-gen alternative for authentication as soon as it's released in our tool ecosystem.
Does your company assess the security and privacy practices of all third-party companies with access to customer data?
Yes. We annually review all 3rd parties according to our Third-Party Risk Management process, which is audited yearly as part of our ISO-27001 certification. This includes risk assessments, background verification checks, ensuring the right clauses are part of the contract, training and awareness, etc.