How we handle institutional data.
Adminformatics is built for academic medical centers, research universities, and institutions with real compliance obligations. This page summarizes our security and compliance posture — for live control monitoring and downloadable reports, visit our Trust Center.
Our Trust Center is the authoritative, always-current view of our compliance program — real-time control monitoring across access, encryption, availability, incident response, and more, with reports and questionnaires available to review, powered by Secureframe.
- SOC 2 Type II documentation
- HECVAT — higher-education security assessment
- VPAT — WCAG, Revised 508, and EN 301 549
- Professional, general, and cyber liability insurance
Compliance posture
Adminformatics is SOC 2 Type II compliant. Our controls cover the Security, Availability, and Confidentiality trust service criteria. Reports and questionnaires are available through our Trust Center.
- Accessibility investment — Accessibility is an active area of investment across every Logix product.
- HIPAA-aligned operations — Administrative, technical, and physical safeguards modeled on the HIPAA Security Rule for tenants handling PHI-adjacent data.
- NIH biosketch / SciENcv compliance — Research Logix outputs conform to current NIH biosketch format and SciENcv data structures.
Data handling
- US-based hosting in audited cloud regions.
- Encryption at rest using AES-256.
- Encryption in transit using TLS 1.2 or higher.
- Tenant isolation enforced at the application and database layer.
- Role-based access control with principle of least privilege.
- Comprehensive audit logging across administrative actions.
Subprocessors
Adminformatics relies on a small set of vetted subprocessors for hosting, identity, and operational tooling.
| Subprocessor | Purpose | Region |
|---|---|---|
| Amazon Web Services (AWS) | Application hosting, storage | US |
| [Identity Provider] | Authentication infrastructure | US |
| [Email Delivery] | Transactional email | US |
Full subprocessor list available on request.
Institutional policies
- FERPA considerations — When tenant data includes student records, Adminformatics operates under the institution's FERPA program as a school official with a legitimate educational interest.
- IRB data handling — Configurations available to align with institutional IRB data classification and access requirements.
- Retention and deletion — Tenant data is retained for the term of the contract and securely deleted within 90 days of contract termination, unless a longer retention period is required by law or contract.
Reporting a security issue
If you believe you've discovered a security vulnerability in any Adminformatics product, please report it directly to our security team. We acknowledge reports within two business days.
