Trust & security

Two columns. The second one is how you judge the first.

What is implemented today, and separately, everything that is not — including every certification we do not hold. Nothing on this page is a badge, because we have not earned one.

No SOC 2. No HITRUST. No ISO 27001. Said here rather than buried on a trust page nobody links to.

Start with the scope, because it decides everything else

Adelo CRM is scoped to exclude patient information. It holds practices, providers, opportunities, calls and routes — provider-level commercial data, which is what a vendor target file contains — together with your own reps’ activity. It is not a clinical system, it has no patient record, and no field in it is designed to accept a patient identifier, diagnosis, encounter or result. Because it does not receive or maintain protected health information on your behalf, it does not act as a business associate and no BAA is required.

That is a product decision, not a legal position taken after the fact. Keeping patient data out of a field-sales system is what lets a commercial team stand it up in days rather than running the review a clinical system would rightly require — and it means the worst case for a breach here is a competitor learning your target list, which is serious, but is a different order of harm from a patient record.

It also draws a line for what belongs in a call note. What was discussed with a provider, what was left behind, what the practice manager said about their draw partner: in scope. Anything about a named patient: not, and reps should be told that plainly at rollout.

Column one

What is implemented today

Each of these is in the architecture now, and we will walk your security reviewer through any of them.

Scoped to exclude patient information
Adelo CRM holds practices, providers, opportunities, calls and routes. It is not a clinical system, has no patient record, and there is no field in it designed to accept a patient identifier, diagnosis, encounter or result. This scoping is the primary control rather than a disclaimer: the most reliable way to protect patient data is not to hold it.
Tenant isolation enforced in the database
Isolation runs on Postgres row-level security policies attached to the tables themselves, not on application code remembering to add a filter. Every row carries its owning organization, and read and write policies check the caller's organization on every query. A missing WHERE clause in application code cannot leak another tenant's data, because the database refuses the rows.
Role and territory-scoped access
What a person can see follows their role and their territory. A rep sees their own practices, providers and days; a district manager sees their district; an administrator configures the org. Ownership rules are explicit records rather than implicit behavior, and they arrive switched off so nothing starts reassigning records the day after an import.
Authentication through a managed provider
Sign-in, password reset, session handling and credential storage run on a managed authentication provider rather than a hand-rolled implementation. Sessions expire and reset flows are provider-standard.
Encryption in transit, US data residency
All traffic between clients and the product runs over TLS. Data at rest sits on managed cloud infrastructure in United States regions, with provider-level encryption. Specific regions and the named subprocessor list are provided under the data processing agreement.
No location tracking of people
Routing operates on the coordinates of physician offices. The product does not collect continuous device location, does not maintain a location history for a rep, and has no geofence. A device's position is only read when a rep asks for it: to start the day from where they are standing, it orders that day's calls, and it reaches the server only if the rep chooses to depart from it, as that one day's starting point. A rep can also save the home their days start from, typed as an address or taken from where they stand when they save it; only that rep can read it. A logged call is a claim by the rep, stored as a claim.
Automation that cannot fire by accident
Every workflow and assignment rule generated from an import ships inactive, states in plain English what it would do, and shows a live count of the records it would fire for. Conditions use three-valued logic, so a condition that cannot be evaluated reports as undetermined instead of guessing in the convenient direction. Nulls never coerce into a match.
Nothing writes until you commit
The whole import pipeline is pure functions returning plain objects. A single writer performs the insert, in one pass, after you have seen exactly what will be created. There is no half-written territory to clean up if you change your mind, and no background job quietly mutating your data.
No third-party tracking on this website
No Google Analytics, no advertising pixels, no session recorders, no cross-site identifiers, no fingerprinting. Page views are counted first-party against a random identifier in a first-party cookie, and are skipped entirely — no request, no cookie — when your browser sends a Do Not Track or Global Privacy Control signal.

Column two

What is not in place

Written out rather than left off the page. If any of these is a hard requirement for you, it is better that you know in week one.

SOC 2 — not certified
No audit has been completed and no report exists. An independent assessment is planned; nothing has been performed yet.
HITRUST — not certified
No certification held and no engagement begun.
ISO 27001 — not certified
No certification held and no engagement begun.
Independent penetration test — not yet performed
Third-party security testing is on the roadmap. We have not commissioned one, so there is no report to share and we will not describe an internal review as if it were one.
Uptime SLA — contractual, but with no operating history behind it
The Master Subscription Terms commit to a 99.5% monthly availability target with service credits, and a subscription customer can hold us to it. What does not exist yet is a track record: we have not been running long enough to publish historical uptime, and a target is a promise rather than evidence. There is no public status page today.
SSO and SCIM provisioning — not self-serve
Single sign-on and directory-based provisioning are an integration conversation rather than a setting you can switch on today. If either is a hard requirement, raise it in week one and we will tell you plainly where we are for your identity provider.
Exportable tenant-wide audit log — on the roadmap
Record changes are recorded by the database itself — a trigger on every governed table writes who changed which field, from what, to what — and are visible in the product. A single exportable, tamper-evident log covering every administrative action across a tenant is not available today.
Formal vulnerability management program — being documented
We patch dependencies and respond to reports, but a documented program with defined severity classes and remediation windows is being written rather than in operation.
Data processing addendum — template stage
A DPA exists as a working template and has not been through counsel. For a customer, the governing document is the executed agreement, and we will not pretend the template is one.

Data handling

What we hold
The contents of the territory files you import — NPI, provider name, specialty, practice, address and the vendor’s own ranking and volume columns — plus the objects the product derives from them: practices, providers, opportunities, tiers, zones, planned days, routes, stops, tasks and logged calls. Messages between colleagues inside your workspace, and any photograph attached to one. Also your users’ names, work email and role.
What we do not hold
Patient records, patient identifiers, diagnoses, results or any clinical data. No continuous device location for any person. No payment card data — billing runs outside the product.
Who owns it
You do, including the imported target file. It is exportable on request and deleted on request, subject to whatever retention your own policy or your data vendor’s license requires of you.
Do you sell or broker data?
No. Adelo Health, LLC has no advertising business and no data-brokerage business. Your target file is not aggregated, resold, benchmarked against another customer’s, or used to build a product we then sell back to you.
Do you use customer data to train models?
No. And more usefully: the planning pipeline is not a model. Scoring, zoning, cadence and routing are deterministic arithmetic with published weights, which is why the product can explain every number it produces and why there is nothing here that benefits from training on your data.
Where is it processed?
Stored and served from managed cloud infrastructure in United States regions. One exception, stated rather than buried: road geometry between planned stops is fetched from a routing provider, server-side, and that request carries coordinate pairs only — no provider, practice or user record leaves the product. Specific regions and the current named subprocessor list are provided under the data processing agreement.

Subprocessors

The categories of third party involved in delivering the product.

  • Cloud infrastructure

    Compute, storage and networking, in United States regions.

  • Managed database and authentication

    Postgres hosting and the managed identity provider behind sign-in.

  • Account email

    Delivery of sign-in confirmation and password-reset email. Nothing else is emailed from the product.

  • Road geometry and map tiles

    The routing provider that returns the road shape of each planned leg, and the vector-tile server behind the map. Both receive coordinates only — a leg's two endpoints, the tiles a map view needs — and no provider, practice or user record is sent.

  • Optional: distance matrix provider

    Only when you configure one for measured drive times. Planning runs without it, and billing is on your own account.

The current list of named subprocessors, with locations and purposes, is provided as part of the data processing agreement and on request to security@adelohealth.com. We will publish a maintained public list, with advance notice of changes, as part of the same work that produces a formal availability commitment.

This website, specifically

Marketing sites are usually where the privacy story quietly falls apart, so here is exactly what this one does.

There are no third-party analytics SDKs on this site. No Google Analytics, no advertising pixels, no session recorders, no cross-site identifiers, no fingerprinting, and no web fonts fetched from anyone else’s server.

Page views are recorded first-party by our own endpoint, against a random identifier in a first-party cookie you can clear at any time. If your browser sends DNT: 1 or Global Privacy Control, tracking is skipped entirely — no request is made and no cookie is written at all.

Form submissions are used to answer your request and are stored in our own CRM. They are not sold and not fed to an advertising platform. Full detail is in the privacy notice.

Security questions we get

No. No audit has been completed and no report exists. We will not put a badge on this site implying otherwise, and we will not tell you one is 'in the final stages' when it has not started.

An independent security assessment is planned. When it happens we will say what type it was, who performed it, what it covered, and what it found.

Send us the questionnaire.

We will answer all of it, including the questions where the honest answer is 'not yet' — and those answers will be marked as such rather than softened.