Skip to content
AdminformaticsAdminformatics
Trust & Security

How we handle institutional data.

Adminformatics is built for academic medical centers, research universities, and institutions with real compliance obligations. This page summarizes our security and compliance posture — for live control monitoring and downloadable reports, visit our Trust Center.

Adminformatics Trust Center

Our Trust Center is the authoritative, always-current view of our compliance program — real-time control monitoring across access, encryption, availability, incident response, and more, with reports and questionnaires available to review, powered by Secureframe.

SOC 2 Type IIHECVATVPAT · Section 508 / WCAGTexas RAMP
Visit the Trust Center
Available to review or request
  • SOC 2 Type II documentation
  • HECVAT — higher-education security assessment
  • VPAT — WCAG, Revised 508, and EN 301 549
  • Professional, general, and cyber liability insurance
01

Compliance posture

SOC 2 Type II compliantSecurity program active

Adminformatics is SOC 2 Type II compliant. Our controls cover the Security, Availability, and Confidentiality trust service criteria. Reports and questionnaires are available through our Trust Center.

  • Accessibility investment — Accessibility is an active area of investment across every Logix product.
  • HIPAA-aligned operations — Administrative, technical, and physical safeguards modeled on the HIPAA Security Rule for tenants handling PHI-adjacent data.
  • NIH biosketch / SciENcv compliance — Research Logix outputs conform to current NIH biosketch format and SciENcv data structures.
02

Data handling

  • US-based hosting in audited cloud regions.
  • Encryption at rest using AES-256.
  • Encryption in transit using TLS 1.2 or higher.
  • Tenant isolation enforced at the application and database layer.
  • Role-based access control with principle of least privilege.
  • Comprehensive audit logging across administrative actions.
03

Subprocessors

Adminformatics relies on a small set of vetted subprocessors for hosting, identity, and operational tooling.

SubprocessorPurposeRegion
Amazon Web Services (AWS)Application hosting, storageUS
[Identity Provider]Authentication infrastructureUS
[Email Delivery]Transactional emailUS

Full subprocessor list available on request.

04

Institutional policies

  • FERPA considerations — When tenant data includes student records, Adminformatics operates under the institution's FERPA program as a school official with a legitimate educational interest.
  • IRB data handling — Configurations available to align with institutional IRB data classification and access requirements.
  • Retention and deletion — Tenant data is retained for the term of the contract and securely deleted within 90 days of contract termination, unless a longer retention period is required by law or contract.
05

Reporting a security issue

If you believe you've discovered a security vulnerability in any Adminformatics product, please report it directly to our security team. We acknowledge reports within two business days.

security@adminformatics.com