Trust is the foundation of what we do. This page lays out how we protect your data, the standards our controls are built around, and how to request documentation for your own due diligence.

Our information-security program is built around the ISO 27001 framework — risk assessment, documented controls, and continuous monitoring across service delivery.
We implement and document controls mapped to SOC 2 (security, availability, confidentiality) and HIPAA safeguards for protected health information — the evidence auditors and insurers request.
For financial, accounting, benefits, and TPA firms, our controls and documentation map to FTC Safeguards and DOL cybersecurity guidance.
For healthcare and other regulated clients handling PHI, Philotech executes a HIPAA Business Associate Agreement (BAA) as part of onboarding.
Identity, productivity, and security — managed end to end for your team.
Enterprise endpoint protection and managed detection & response powering every PhiloSecure plan — including MESH, its email-security layer that filters phishing and payment-fraud attempts before they reach the inbox.
Immutable, cloud-first backup and disaster recovery built for SMBs.
Business password management, available on all plans, to eliminate the reused and weak credentials behind most breaches.
For due diligence, vendor assessments, or regulatory audits, our team can provide documentation covering our security posture and controls. Depending on what your reviewers need, that can include a security overview, our control mappings, a HIPAA Business Associate Agreement, proof of cyber-liability insurance, and completed security questionnaires — shared under NDA where appropriate.
The firms that ask the hardest questions make the best clients. Bring yours.