How we protect your health center's quality-improvement data.
All traffic to MeasureWise is encrypted with TLS 1.2+ in transit. Data at rest uses AES-256 encryption at rest on managed Postgres infrastructure (AWS us-east). Database backups are encrypted using the same standard.
Every table that holds organization data has Postgres Row-Level Security policies scoped by organization_id. Users cannot read, write, or even count rows belonging to another health center — enforced at the database layer, not just in application code.
MeasureWise is designed for operational and quality-improvement workflows using aggregate, de-identified, or non-patient-identifying information. Because MeasureWise is not intended to collect, store, transmit, or process protected health information (PHI), a Business Associate Agreement (BAA) is not offered or required. Organizations should not enter patient-identifying information into the platform.
Email verification is required before sign-in. Passwords must meet complexity requirements and are checked against the Have I Been Pwned database. Optional Google SSO is available. Inside each organization, access is governed by role-based access controls (org admin, standard user).
Hosted on infrastructure provided by vendors with SOC 2 Type II attestations. MeasureWise itself does not hold a SOC 2 certification. The database is backed up automatically every day with 7-day point-in-time recovery, and backups are stored encrypted.
Managed Postgres and authentication hosting, Stripe (payments), Resend (transactional email), and Lovable AI Gateway (AI Quality Assistant). We do not sell or share your data with third parties for marketing.
If you believe you've found a security issue, email hello@measurewise.org with the subject line "Security". We acknowledge security reports within 1 business day.
Security questions or vendor-review questionnaires?
Email hello@measurewise.org and we'll respond within 1 business day.