Learn about our security measures and compliance certifications
The SOVA IRB Management System is built with security as a foundational principle. We employ industry-leading security practices to protect sensitive research data and ensure regulatory compliance. Our infrastructure is designed to meet the stringent requirements of clinical research and healthcare data protection.
Built-in security measures protecting your data
All data is encrypted using AES-256 encryption when stored
TLS 1.3 encryption for all data transmission
Role-based access control (RBAC) with principle of least privilege
Comprehensive audit trails for all system actions
Regulatory standards we adhere to
Health Insurance Portability and Accountability Act compliance for PHI protection
FDA regulations for electronic records and signatures in clinical research
General Data Protection Regulation for EU data subjects
Service Organization Control audit for security, availability, and confidentiality
How we protect your account and data
All user accounts require MFA for access. We support authenticator apps, SMS, and hardware security keys.
Automatic session timeout after 30 minutes of inactivity. Users can view and revoke active sessions.
Minimum 12 characters with complexity requirements. Password history prevents reuse of last 10 passwords.
Organizations can restrict access to specific IP addresses or ranges for additional security.
Automated daily backups with 90-day retention. Geographic redundancy across multiple data centers.
Regular security assessments, penetration testing, and automated vulnerability scanning.
Our commitment to security incident handling
We maintain a comprehensive incident response plan that includes:
Help us maintain a secure environment
If you discover a security vulnerability or have concerns about the security of our system, please report it immediately:
Security Team Contact
security@sova.healthWe take all security reports seriously and will respond within 24 hours. Responsible disclosure of vulnerabilities is appreciated.