法律条款 · Security

Data Security

How we protect the data researchers collect — encryption in transit and at rest, continuously monitored controls with a public live trust report, HIPAA safeguards under a signed BAA, and EU data residency.

更新于 2026年8月21日Expimetrics, Inc. d/b/a ExpiWell

1Our Commitment

ExpiWell applies industry-leading standards to safeguard customer data and the data collected for research. Compliance is not asserted once a year and left to age: the controls behind it are monitored continuously by Vanta, and the current status of every monitored control is published in a live trust report that anyone can open — no account, no NDA.

The platform is used routinely for research that captures Protected Health Information (PHI), and the practices below are the standing description of how that data is protected. For questions that go beyond this page, contact security@expiwell.com.

2Encryption

All data transferred between the browser or the mobile apps and ExpiWell's servers is encrypted in transit using Transport Layer Security (TLS). All stored data is encrypted at rest with AES-256.

3Hosting and Infrastructure

Services run in the data centers of a major cloud infrastructure provider that meets the requirements of security-sensitive organizations while providing data privacy. We select that provider for its certification against ISO/IEC 27018 — the international code of practice for protecting personal data in the cloud, alignment with which is assessed by an independent assessor rather than self-declared. Servers are protected by firewall systems, and vulnerability scans run regularly so that any gaps are found and patched quickly.

Reviewers who need the provider named — together with its current certification and our signed Business Associate Agreement — can request all three from security@expiwell.com.

4HIPAA

Platform security and privacy comply with the Health Insurance Portability and Accountability Act. Concrete measures include:

  • Data encrypted at rest and in transit
  • Backup, continuity, and disaster-recovery processes — established and tested
  • Vulnerability and system monitoring procedures
  • Two-factor authentication required on all accounts, with passkey support
  • Anti-malware technology, employee background checks, and HIPAA training for all employees
  • Physical safeguards at our hosting provider, guaranteed by a signed Business Associate Agreement

5GDPR and Data Residency

Separate US and EU deployments keep EU resident data in the EU region, and ExpiWell has appointed EU and UK GDPR representatives. The GDPR policy describes the controller/processor responsibility split, the Article 28 data-processing contract, and the representatives' contact details; the privacy statement describes what is collected, why, and for how long. For a formal statement of compliance, contact security@expiwell.com.

6Access Control

Two-factor authentication is required on all accounts, and passkeys are supported. Complex password requirements are enforced on every account.

Subscribers control their own users and data, so part of the protection is practiced on your side of that line: strong passwords, never stored in easily accessible places, and account access restricted to the people authorized to see the data.

7Data Deletion and Retention

Researchers control their own participant data and may request that any of it be deleted; it is removed from ExpiWell's databases immediately. Daily backups retain deleted data for 8 days, after which it is removed from ExpiWell's servers automatically.

8Verify It Yourself

The live trust report shows the real-time status of every monitored control and answers to the questions institutional reviewers ask most. It is the same set of answers we hand to IRBs and university security reviews, and it updates as the controls are checked — not when someone remembers to edit a page.