Verified controls, stated plainly.
DayLoom Solutions, Inc. publishes only the controls and attestations that are in place today. Nothing on this page is aspirational.
SOC 2
SOC 2 Type II attestation completed November 2025. Scope: Security, Availability, and Confidentiality of the DayLoom Cloud Platform.
HIPAA
BAA provided to all clients. DayLoom supports administrative workflows and does not make clinical determinations.
Encryption
AES-256 for data at rest and TLS 1.3 in transit, across the DayLoom Cloud Platform.
RBAC, MFA, and SSO
Role-based access control keeps billing, clinical-adjacent, and front-desk views separate. MFA is required for every user, and SAML 2.0 SSO is available for multi-location groups.
Override and approval logging
Every approval, edit, rejection, and override is written to an audit log with the acting user and timestamp.
Retention
PII is retained for 7 years per HIPAA-aligned recordkeeping guidelines. System logs are retained for 30 days.
Where DayLoom stops and staff decide.
DayLoom prepares and organizes administrative work. Staff approve patient-facing messages, coverage statements, claim narratives, and clinical escalations.
- SOC 2 Type II
- Attestation completed November 2025
- Scope: Security, Availability, and Confidentiality of the DayLoom Cloud Platform.
- HIPAA
- BAA provided to all clients
- Encryption
- AES-256 at rest; TLS 1.3 in transit
- Access control
- Role-based access control (RBAC) with MFA required
- SAML 2.0 SSO available for multi-location groups.
- Audit logging
- Every approval, edit, and override is logged with user and timestamp
- Retention
- PHI retained 7 years; system logs retained 30 days
- Data residency
- AWS US-East-1
- Subprocessors
- AWS, Twilio, Stripe
Scopes are limited to read:schedule and write:notes. DayLoom does not access clinical chart notes or diagnostic images.
If an API connection fails, DayLoom flags the Day Map as stale and alerts the office manager to verify manually.
Conflicting patient data triggers a Review Required flag and notifies the Practice Manager by push notification.
Questions from your security reviewer?
Email security@dayloom.website for the SOC 2 report, our BAA, or a subprocessor list.