Backup & Security

Enterprise infrastructure, in your own accounts.

Everything we build runs on enterprise cloud platforms, in accounts you own. Their security, encryption, backups and redundancy come built in, and we set them up the way industry best practice says they should be.

Free 30-minute conversation about how your business runs. Practical recommendations. No obligation.

Prefer to talk? Call (435) 243-5808 about your workflow, or .

The short version

Built on the platforms enterprises use.

We deploy on the same infrastructure large companies rely on, with enterprise-grade security and encryption built in, and use the providers' own backup and redundancy rather than inventing our own.

  • AWS
  • Microsoft Azure
  • Google Cloud
  • Cloudflare
  • Neon
  • Vercel
  • GitHub
  • PostgreSQL
  • n8n
  • More+
  • Runs in cloud accounts you own, never on ours
  • Encrypted in transit and at rest, with the providers' built-in encryption
  • Automated backups and redundancy from the providers, with restores tested during support
  • Access by role, with multi-factor sign-in and a log of who did what
  • Secrets in the providers' secret stores, never in the code
Industry best practices

The practices we follow on every build.

None of these are extras. They're how every system we build is set up from the first deployment.

Encryption

Data is encrypted in transit and at rest, using the encryption the providers build into their storage, databases and networks. Connections between systems use encrypted channels only.

Access and sign-in

Access is granted by role, on the least privilege each person needs, with multi-factor sign-in. Everyone uses a named account, so access can be removed for one person without touching anyone else.

Secrets and credentials

Passwords, keys and tokens live in the providers' secret stores, never in the code or a shared document, and there's a written runbook for rotating them.

Backups and recovery

We switch on the providers' automated backups, with point-in-time recovery wherever the platform supports it. Restores are tested as part of ongoing support rather than assumed to work.

Redundancy

Storage and databases use the providers' built-in replication across separate data centers, so one failure doesn't take the system down or lose data.

Monitoring and audit logs

Every automated step and every change is logged. Alerts go out when something fails, stalls or behaves unusually, and the logs are yours to keep and export.

Updates and patching

Security patches and dependency updates go in on a set cadence, tested before they reach production.

Separate environments

Development, staging and production are kept apart, and real customer data isn't copied into development.

Least exposure

Systems only connect to what the workflow needs. Integrations use access you grant and can take back, and nothing is left open to the internet that doesn't need to be.

By industry

What changes with the data you hold.

Home Services: Customer and payment data

Card numbers never touch anything we build. Payments run through your existing processor, and our side only keeps the record that a payment happened. Customer addresses, gate codes and equipment histories stay in your own systems.

  • Payments through your existing processor
  • Customer records in systems you control
  • Access by role for office and field
  • A log of every automated change
Professional Services: Data handling

Your clients send security questionnaires because they want to know where their information goes. You can answer plainly: anything we build lives in your own cloud account, connections use access you grant and can take back, and there's a log of what ran and when.

  • Anything we build lives in your own cloud account
  • Access by role and by client
  • A log you can export
  • No vendor of ours holding your client list
Healthcare: Regulated data

Healthcare is more than HIPAA. A practice, a medical supply company, a device manufacturer and an IPA each answer to different rules, and what we build is designed around the ones that apply to you. Chris Barbieri, one of Loque Logic's principals, has run a medical supply business under HIPAA at national scale, so regulated data isn't a new conversation for us.

We sign a business associate agreement (BAA) with you, and every platform in the solutions we build that touches protected health information is covered by its own BAA. All of our solutions are designed to be HIPAA and HITECH compliant, with data encrypted throughout its journey and in storage. Compliance also depends on how your organization uses a system, so we'll show you exactly how yours is set up and your compliance lead can check it.

  • A BAA from Loque Logic, and from every platform that touches the data
  • Designed to be HIPAA and HITECH compliant
  • Encrypted throughout its journey and in storage
  • Anything we build lives in your own cloud account
  • Access by role, with time-stamped audit trails

Practices and clinics

  • HIPAA and HITECH, with a BAA from us and every platform involved
  • Stronger handling for substance use disorder records under 42 CFR Part 2
  • Information blocking rules on sharing health information
  • Consent rules for automated texts and calls to patients

Medical supply and DME

  • HIPAA and HITECH, with BAAs in place and card payments kept with your processor
  • Medicare DMEPOS supplier standards and accreditation
  • Order, prescription and proof-of-delivery records kept ready for audits

Device manufacturers

  • FDA's Quality Management System Regulation, aligned with ISO 13485
  • Time-stamped audit trails and electronic signatures under 21 CFR Part 11
  • Device and lot traceability for complaints and corrective actions

IPAs and health plans

  • HIPAA and HITECH, with BAAs from us and every platform involved
  • Delegated credentialing to NCQA standards, with oversight records
  • Standard claims, eligibility and authorization transactions
  • Security reviews such as HITRUST or SOC 2 questionnaires, answered with how your system is set up
FAQ

Questions people ask

Where is our data stored?
In cloud accounts you own, with the provider and region chosen during scoping. It isn't held on Loque Logic's servers, because we don't run any for client data.
Who can see our data?
The people you grant access to. We work through named accounts you control while we build and support the system, and you can remove that access whenever you like.
What happens if a provider has an outage?
The providers' redundancy handles most failures without anyone noticing. For the rest, the runbooks cover how to recover, and backups mean data can be restored to a point in time.
Is Loque Logic certified?
No, and we won't claim to be. The platforms we deploy on hold their own certifications, such as SOC 2 and ISO 27001. Those cover the providers' infrastructure. How a system is set up and used matters just as much, so we'll show your security or compliance lead exactly how yours is configured.

What is manual work costing your business?

Repetitive admin, missed follow-ups and disconnected systems take time away from running your business. Bring us one process that slows your team down. We'll help you understand what could improve, how much time you could recover, and what it might cost to implement.

Get My Free Workflow Review

Free 30-minute conversation about how your business runs. Practical recommendations. No obligation.

Not sure where to start? That's what the free call is for. We'll walk through how your business runs and find the easiest wins, the places where automation and AI agents can take work off your team first.

Prefer to talk? Call (435) 243-5808 about your workflow, or .