The platforms we build house sensitive client health information, treatment histories, and billing data. We apply enterprise-grade security practices to every deployment.
Infrastructure Security
We deploy on established cloud infrastructure providers that maintain SOC 2 Type II and ISO 27001 compliance. All data at rest is encrypted with AES-256, and all data in transit is protected with TLS 1.3.
Application Security
- Authentication: Hardened session management with support for multi-factor authentication on manager and admin accounts.
- Access control: Role-based permissions ensure a provider, front-desk staff, or manager can only view records their role is authorized to access.
- Client record protection: Treatment history and consultation forms scoped to authorized staff only.
- Audit logging: Key actions on client records, billing, and staff access are logged for review.
Payment Security
LJBodyworks does not store credit card numbers on our own servers. All payment processing is handled through PCI-DSS Level 1 certified providers.
Vulnerability Reporting
If you believe you've found a security vulnerability in our systems or in a platform we've deployed for a client, please email security@ljbodyworks.us. We respond to all reports within 48 hours.