Access controls
Users access AltraSync through authenticated accounts. Permissions are managed by role and company. Super Admin controls global settings, company users are isolated by tenant/company, and regular users only see the areas granted to them.
Login protection
- Mandatory recovery email setup for user accounts.
- Email two-factor verification where configured.
- Failed-login lockout and session timeout controls.
- Optional single-login enforcement to replace older sessions.
Data location
Azure production uses a persistent data root under /home/aba_audit_data. Code is deployed from GitHub, while database files, uploads, support attachments, logs, and backups stay in the Azure persistent data area.
Retention safety
Retention cleanup is designed to remove expired PHI-heavy document/evidence files while keeping safer operational history such as status, logs, and counts. Cleanup should never delete users, companies, settings, or audit history.
AI safety
AI features are admin-controlled. Dashboard trend summaries use aggregate company counts only and do not show token usage to normal dashboard users. Token logs are restricted to Super Admin AI Settings.
Support safety
Support tickets include request metadata to help Super Admin resolve issues. Users are reminded not to paste or attach PHI unless necessary and approved.
Incident handling
Suspected security or privacy incidents should be reported promptly through Support or to support@altrasync.com. AltraSync support should preserve relevant logs and coordinate with affected customers for review.
Official resources
For general healthcare security background, users can review HHS resources for the HIPAA Security Rule and HIPAA Privacy Rule.