Compliance & Security

Enterprise-grade compliance. Built in, not bolted on.

Altered Dimensions maintains rigorous compliance with SOC 2, HIPAA, and PCI-DSS frameworks. Every server, every process, every audit — verified and documented.

SOC 2 Type II
Audited annually
HIPAA
PHI protected
PCI-DSS Level 1
Highest certification
SOC 2 Type II

SOC 2 Type II Compliance

SOC 2 (System and Organization Controls) is a framework developed by the AICPA that ensures service providers securely manage your data. Our Type II audit covers a minimum 6-month observation period, validating that our controls are not just designed properly — but operating effectively over time.

We are audited annually by an independent AICPA-accredited firm. Our SOC 2 report covers all five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

Trust Service Criteria Covered

Security
Firewalls, IDS/IPS, MFA, encryption at rest and in transit, vulnerability management, and penetration testing.
Availability
99.99% uptime SLA, redundant infrastructure, automated failover, capacity planning, and DDoS mitigation.
Processing Integrity
Quality assurance, monitoring, change management, and automated validation of system processes.
Confidentiality
Data classification, access controls, NDAs, encryption, and secure disposal of sensitive information.
Privacy
GDPR-aligned data handling, consent management, data subject rights, and privacy-by-design architecture.
HIPAA Compliant

HIPAA Compliance for Healthcare Data

The Health Insurance Portability and Accountability Act (HIPAA) sets the standard for protecting sensitive patient data. Any company that deals with Protected Health Information (PHI) must ensure all required physical, network, and process security measures are in place.

Altered Dimensions offers HIPAA-compliant hosting with a signed Business Associate Agreement (BAA). Our infrastructure meets all HIPAA Security Rule requirements, including administrative, physical, and technical safeguards.

HIPAA Safeguards Implemented

Administrative Safeguards
Security officer designation, workforce training, access management policies, incident response procedures, and regular risk assessments.
Physical Safeguards
Biometric datacenter access, 24/7 surveillance, visitor logging, environmental controls, and redundant power/cooling systems.
Technical Safeguards
AES-256 encryption at rest, TLS 1.3 in transit, audit logging, automatic logoff, unique user identification, and emergency access procedures.
Business Associate Agreement (BAA)
We execute a BAA with every healthcare client before processing any PHI. Available upon request for Enterprise and HIPAA-qualified plans.
PCI-DSS Level 1

PCI-DSS Level 1 Compliance

The Payment Card Industry Data Security Standard (PCI-DSS) is the global standard for securing payment card data. Level 1 is the highest certification, required for organizations processing over 6 million Visa transactions annually — and the gold standard for any business handling cardholder data.

Our infrastructure undergoes annual on-site assessments by a Qualified Security Assessor (QSA), quarterly network scans by an Approved Scanning Vendor (ASV), and continuous internal monitoring.

PCI-DSS Requirements Met

1
Install & maintain a firewall
Network segmentation, WAF rules, and deny-by-default policies.
2
Protect cardholder data
AES-256 encryption at rest, TLS 1.3+ in transit, tokenization support.
3
Vulnerability management
Anti-virus, patch management, and automated vulnerability scanning.
4
Strong access controls
MFA, role-based access, least privilege, and unique IDs for all personnel.
5
Monitor & test networks
24/7 SIEM logging, quarterly ASV scans, annual penetration testing.
6
Information security policy
Documented policies, annual reviews, employee training, and incident response.

Infrastructure

Security controls that power compliance.

Encryption

AES-256 at rest. TLS 1.3 in transit. HSM-backed key management with automatic rotation.

Access Control

MFA enforced. SSO/SAML integration. Role-based access with just-in-time provisioning.

Audit Logging

Immutable logs. 90-day retention. SIEM integration with real-time alerting and anomaly detection.

Vulnerability Mgmt

Weekly automated scans. Quarterly penetration tests. 48-hour critical patch SLA.

Network Security

Next-gen firewalls. WAF with OWASP rules. DDoS mitigation up to 1 Tbps.

Incident Response

24/7 SOC monitoring. Documented IR plan. Tabletop exercises quarterly. Breach notification within 24 hours.

Need a compliance report or BAA?

Our compliance team can provide SOC 2 reports, execute a BAA, or walk you through our PCI-DSS Attestation of Compliance.

Powered by WHMCompleteSolution

Powered by Altered Dimensions