Security & compliance

Your patients' images deserve more than a locked door.

Protected health information is the most sensitive data you hold — and a prime target. Lightbridge is built around the security principles your board, your auditors, and your security team expect, and we can speak to each one in plain language.

The principles

Six commitments, no jargon required.

What each one means for you — with a note on how we deliver it, for the teams who want the detail.

Zero Trust

Nothing and no one is trusted just because they're "inside." Every request to reach your data is authenticated and authorized — every time, from anywhere.

Under the hood: OIDC identity on every interface · verified service-to-service traffic · no implicit network trust.

Defense in Depth

Security isn't a single wall — it's many. Independent, overlapping safeguards mean that if one control ever fails, others still stand between an attacker and your data.

Under the hood: network segmentation · admission policy that blocks risky workloads · least-privilege everywhere.

Encryption everywhere

Your images are scrambled both while moving and while stored — unreadable to anyone without the keys, whether they're on the wire or at rest in the cloud.

Under the hood: TLS at the edge · mutual TLS between components · KMS-backed encryption at rest.

Immutability

Records of what happened can't be quietly changed or erased. The history of your data stays tamper-evident — exactly what an investigation or audit needs.

Under the hood: append-only audit records · digest-pinned software · everything reproducible from code.

Role-Based Access Control

People see exactly what their role allows — and nothing more. A technologist, a radiologist, and an administrator each get the right access, by design.

Under the hood: role-based authorization on UI, imaging APIs, and console · optional multi-factor authentication.

Customer-held Destruction Key

Decommission runs on your authorization, and with customer-managed encryption keys the power to cryptographically erase your data stays in your hands. Any emergency operator action is least-privilege and audited.

Under the hood: customer-managed KMS key (in your account) · customer-authorized teardown gated on completion · operator break-glass audited via CloudTrail.

You're always in control

You control the erasure.

A disaster-recovery archive should never outlive its purpose — and you should never have to wonder whether your data is truly gone. Your data is encrypted with a key you control, so you can cryptographically erase it at any time, and no one — us included — can recover it without that key. Routine decommission runs on your authorization; an emergency operator path exists, as it must in any system, and every use of it is logged for you to see.

  • Customer-managed key — the encryption key lives in your AWS account; we can't read or recover your data without it.
  • Customer-authorized — routine teardown runs on your authorization, and won't run while any of your data is still outstanding.
  • Provably gone — disabling your key cryptographically erases the data; nothing is recoverable.
  • Honest about break-glass — the emergency operator path is least-privilege and every use is logged (CloudTrail), never silent.
No idle attack surface

The safest environment is the one that isn't running.

Most disaster-recovery setups keep a "warm standby" idling 24/7 — which means a standing cost and a standing target. Lightbridge is different by design: your archive is built only when it's needed — during a real crisis or a quarterly DR exercise — and destroyed cleanly afterward. There's simply nothing sitting there to attack, patch late, or let drift out of compliance between events.

  • Nothing to compromise at rest — no standing environment between events, so there's no idle target.
  • No drift, no stale patches — every environment is built fresh from code, current by construction.
  • No idle cloud cost — you pay for the bridge when you use it, not to keep one warm.
We don't hand the threat back

A clean room — and a verified hand-back.

A fair question: if your primary was compromised, doesn't routing imaging through Lightbridge just pass the problem back when you recover? No. Lightbridge stands up as an isolated, zero-trust environment with no link to your damaged systems — the studies you acquire during the outage are captured straight into that clean room, never touching the compromised primary. And when it's time to repatriate, every study is integrity-verified and reconciled before cutover, so what returns to your restored VNA is provably complete and untampered.

  • Isolated clean room — a fresh, segmented environment with no connection to your compromised systems; the new studies are born here, not in the damaged primary.
  • Encrypted end to end — images are encrypted in transit and at rest, unreadable without your keys, the whole way through.
  • Verified before it returns — repatriation pulls, stores, and reads back every study, and a reconciliation gate must pass before cutover — surfacing any exception by name.
  • Optional content integrity — byte-level (PixelData) verification can confirm each image is bit-for-bit intact, not just present.
HIPAA-aligned

Compliance built in, not bolted on.

Lightbridge is designed and operated to support your HIPAA program and a Business Associate Agreement for every engagement — so your imaging continuity plan strengthens your compliance posture instead of complicating it.

  • Encryption in transit & at rest for all protected health information.
  • Access controls & audit logging — every touch of PHI is authorized and recorded.
  • Least-privilege & secret hygiene — scoped permissions, no credentials in plain sight.
  • BAA-ready — operated to support your agreements and your auditors.
For your security team

The detail behind the promises.

Happy to go deeper on any of this — and to prove your data arrives complete and intact, not just that it moved.

Data integrity

When studies move, we read them back and confirm completeness before anything is trusted as recovered — with optional content-level (byte) verification for the studies that matter most.

Hardened by default

Workloads run with least privilege and are admission-checked; risky or unpinned components are blocked outright, not merely flagged.

Reproducible & reviewable

The entire environment is defined as code with pinned dependencies and automated security gates — so what we run is exactly what was reviewed.

Want the architecture-level walkthrough? See the platform →

Bring your security & compliance team.

We welcome the hard questions. Let's walk through the threat model, the controls, and how Lightbridge fits your HIPAA program.