Trust & Safety
Security at Second Set
How Second Set protects access to your information.
Encryption
Second Set is designed to protect sensitive data in transit using TLS 1.2+ and at rest using AES-256 encryption across supported production storage systems.
Authentication
We use industry-standard authentication practices including bcrypt password hashing, JWT-based session tokens, and optional two-factor authentication. The app signs you out after a period of inactivity.
Access Controls
Access to patient records depends on account roles and patient-specific permissions. Connected providers and invited caregivers can access information according to those permissions. Private file downloads also check whether the requesting account is authorized to access the file.
Infrastructure
Second Set runs on enterprise cloud infrastructure with automated backups, DDoS protection, and continuous security monitoring. We use environment isolation to separate production data from development and testing environments.
HIPAA-Conscious Design
Every feature is designed with HIPAA-conscious controls in mind. This includes audit logging, minimum necessary access principles, and Business Associate Agreements with applicable service providers.
Vulnerability Disclosure
If you discover a security vulnerability, please report it responsibly to hello@secondset.health. We take all reports seriously and aim to address confirmed vulnerabilities promptly. We do not pursue legal action against good-faith security researchers.
Questions?
Contact our security team at hello@secondset.health