Mixmax protects user data throughout the data flows of the Mixmax product, from account creation and integration through Google’s OAuth service, to encryption of data in transit to Mixmax servers (using browser-based TLS) and encryption of that data at rest (using AES-256), to a variety of administrative, physical, and technical safeguards designed to create a secure environment for our customers’ data. As a result, the Mixmax product can be implemented within a HIPAA-compliant environment.
We work with industry-leading cloud PaaS and IaaS providers. All Mixmax applications run in a virtual private cloud (VPC) hosted by AWS, including failover and backup instances. User data transferred to Mixmax is hosted by our cloud-based database provider, Mongo, which also store and process the data using industry standard infrastructure. These infrastructure providers maintain industry-standard security certifications, including ISO 27001, ISO 27017, ISO 27018, SOC 1, SOC 2, SOC 3 and PCI DSS Level 1.