SOC2C

Is this your company? Buyers are checking Awell Health here. Claim awellhealth.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Awell Health logo

Awell Health

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Awell Health is SOC 2 Type II compliant. Awell Health also holds ISO 27001, GDPR, and HIPAA.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Awell is a low-code platform used by clinical and product teams to design clinical workflows and integrate them into their tech stack. With Awell, care organizations automate routine clinical tasks, synchronize data between systems and drive seamless coordination between care teams and patients. Awell’s customers have improved the lives of hundreds of thousands of patients across a wide array of medical conditions. They achieved results such as a 50% increase in care team capacity, a 40% reduction in length of stay, and a 25% reduction in emergency room admissions. This report is a live dashbo

Compliance & infrastructure

Hosting
GCP
Data handled
Customer personally identifiable informationPersonal health information

Documents

9

Subprocessors

5
  • G
    Google Cloud Platform · gcp
  • S
    Stytch · Auth Provider
    USA
  • M
    Mailgun · Marketing
    USA
  • O
    Openai · Engineering
    USA
  • T
    TactionSoft · TactionSoft supports Awell in managing and maintaining HL7/ADT integrations (via
    USA (managing localised EU or US infrastructure)

Compliance leadership

The person who leads Awell Health's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Awell Health's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

7/11 details · 64%

SOC2C shows the verified essentials. 4 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Awell Health SOC 2 compliant?
Awell Health is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Awell Health ISO 27001 certified?
According to Awell Health's public trust center, Awell Health is ISO 27001 certified. On SOC2C this listing is Listed.
Is Awell Health GDPR compliant?
According to Awell Health's public trust center, Awell Health is GDPR compliant. On SOC2C this listing is Listed.
Is Awell Health HIPAA compliant?
According to Awell Health's public trust center, Awell Health is HIPAA compliant. On SOC2C this listing is Listed.
Is Awell Health SOC 2 Type I or Type II?
Awell Health is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.

Answers published by Awell Health

Reproduced from Awell Health's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

Where is my data hosted with Awell?
Our deployments are fully regional, so your data can be securely hosted either in Europe, UK or the USA via Google Cloud Platform to meet your compliance needs. This means that by design, the data never leaves the region.
Are you SOC 2 certified?
Yes! Awell has been SOC2 certified since December '24. We've had no exceptions to any of our controls. Feel free to download our report here in the trust center for your own third party risk assessments! Note that we also only work with reputable vendors and third parties that have ISO27001:2022 and/or SOC2 compliance.
Are you covered by NIS2?
Yes, we're considered as an "important" service provider under NIS2 and applied/subscribed to the relevant authorities to meet the requirements. NIS2 is a EU regulation focusing on standardising a level of cyber security controls in important and essential industries.
Do you encrypt data?
Data is encrypted at rest (AES 256) and in transit (HTTPS over TLS1.2+). Our database is deployed on a kubernetes cluster in the Google Kubernetes Engine. It is backed by a kubernetes persistent volume, which is covered by Google Cloud’s Default encryption of data at rest. In cluster db connections use the HTTPS channel and therefore benefit from encryption in transit through TLS. HTTP access to the database is disabled to prevent connections without encryption in transit.
How scalable is Awell?
Our product is deployed on Google Kubernetes Engine, and we use regional clusters which already come with built in redundancy (3 zones per region). We have daily backups in all environments, and the provisioning of new environments is fully automated (IaC) so in the worst case scenario where a google data center is fully down we can create a new deployment in a different datacenter and be up and running with the latest backup in a day at most, but realistically it can be as quick as one hour. Our integrations and infrastructure are designed to handle large volumes of patients. Have a look at our system status page for more information.