<!-- LLM_VERSION_INFO
FORMAT: text/markdown
CONTENT_TYPE: article
ORIGINAL_URL: https://noyo.com/blog/6-ways-noyo-keeps-data-secure
ALTERNATE_VERSION: blog/6-ways-noyo-keeps-data-secure/index.html (text/html)
EXTRACTION_DATE: 2026-04-17T01:18:23.049Z

This is the markdown version with text-only content (images converted to alt-text).
For rich formatting with images, request the HTML version at: blog/6-ways-noyo-keeps-data-secure/index.html
-->

Mar 13, 2023

## 6 ways Noyo is raising the bar for data security

At Noyo, we help our customers maintain the trust they’ve worked so hard to build by providing them with industry-leading data security protocols, processes, and most importantly, partnership. Here are 6 ways we keep their most sensitive data safe.

Ashley Medina

Whether you work for an insurance carrier, a benefits platform, or a brokerage, you know it takes years to build trust with partners and customers.

At Noyo, we help our customers maintain the trust they’ve worked so hard to build by providing them with industry-leading data security protocols, processes, and most importantly, a partnership.

Here are six reasons why our partners trust Noyo with their most sensitive data.

## 1. We’re SOC 2 Type II audited

SOC 2 Type II reports include the most comprehensive security compliance standards within the [Systems and Organization Controls](https://www.aicpa.org/resources/landing/system-and-organization-controls-soc-suite-of-services) (SOC) framework to demonstrate how effectively and consistently a service organization handles sensitive information. These audits evaluate both the suitability of a company's security controls, in addition to confirming if they remain implemented successfully over an extended period of time.

At Noyo, we go a step further by having a respected, well-recognized third-party audit firm [Linford & Company](https://linfordco.com/) perform annual evaluations and provide feedback on our performance in three important areas.

- **Security**: External auditors use a top-down approach to assess leadership’s effectiveness in establishing, communicating, and maintaining a compliance program, supported by information security policies and ethical standards for personnel. They look at how this permeates throughout the organization, including various technical controls around IT, engineering, and HR processes.

- **Confidentiality**: We rely heavily on a third-party to ensure all our policies and processes effectively maintain the confidentiality of protected health information ( [PHI](/content/blog/why-apis-solution-for-benefits-administration-insurance-carriers/index.html)) and personally identifiable information (PII).

- **Availability**: Ensuring our system maintains industry standards for operational uptime is vital to serving our customers and partners. External auditors help validate our business continuity plans and disaster preparedness.

Bringing in auditors to evaluate our practices in an objective manner is a significant investment — one that many competitors don’t make. At Noyo, our [product philosophy](/content/blog/what-three-lessons-are-most-important-to-noyos-new-vp-of-product/index.html) leverages these annual audits to ensure we’re always learning and investing in continuous security improvements.

## 2. We go beyond standard HIPAA compliance

Similar to our approach to SOC 2 Type II compliance auditing, we also go the extra mile in ensuring our business processes and security controls align with HIPAA. We engage [Techumen](https://techumen.com/), a third-party auditor, to perform an assessment of our ability to understand and follow the [HIPAA Security Rule](https://www.hhs.gov/hipaa/for-professionals/security/index.html).

**By engaging in one we ensure:**

- All our core and related security controls align with the Rule.
- We execute business associate agreements (BAAs) for any suppliers that handle our customers’ data.
- Any tools that support our operations (e.g., our customer support ticketing tool) are configured to minimize data exposure.

HIPAA audits typically apply only to certain health organizations like hospitals and integrated delivery networks. At Noyo, we go one step beyond by voluntarily engaging an auditor to look specifically at the HIPAA controls that apply to us. It’s an added measure and a great way for us to get additional feedback we can leverage in our commitment to continuous improvement.

According to the 2022 HIPAA Gap Assessment conducted by Techumen, Noyo is in the top five of organizations in our class in implementing the HIPAA Security Rule.

## 3. We use short-lived API tokens

An API token is a form of access control that’s similar to the username-and-password combination most of us use every day for email and other applications. Noyo uses the [OAuth 2.0 protocol](https://oauth.net/2/) to generate tokens that only remain valid for 10 minutes. This significantly reduces the window for potential damage if a token is compromised.

## 4. We apply highly granular data access protocols

The sheer amount of data being shared across multiple touchpoints within the benefits ecosystem implies a certain amount of risk. We implement layers of controls to minimize the impact of unauthorized access, allowing us to act swiftly in the event of a security incident.

**Our data access protocols include:**

- A unified data access model that ties all elements within our system to clear owners and users.
- A cloud infrastructure that deploys and maintains searchable logs.
- An authentication system for all Noyo employees that creates an audit trail and reduces risks.

## 5. We ensure data is encrypted both at rest and in transit

Noyo protects our customers’ data 24/7, ensuring security whether it’s being stored or transmitted. We use the 256-bit AES encryption algorithm for data at rest and the TLS 1.2+ encryption protocol for data in transit.

**Additional Noyo encryption safeguards include:**

- An internal monitoring tool for real-time alerts on encryption failures.
- Alerts for security misconfigurations and vulnerabilities.

## 6. We work with carriers to meet their unique needs

The greatest value Noyo provides in terms of data security comes from our commitment to partnering with carriers. Each carrier has unique needs and levels of risk they face. Once trust is established, it [unlocks innovation](/content/solutions/index.html) that otherwise wouldn’t be possible.
