Security

Security is thearchitecture.

End-to-end encrypted, on-premise data, zero trust by design. OpenShare sets up the connection and never sees your PHI, even when traffic falls back to a relay.

How your data stays secure.

Four architectural principles that protect healthcare data at every layer.

End-to-end Encryption

All data encrypted in transit using WebRTC DTLS. Your data is unreadable to anyone outside the connection, including OpenShare.

On-Premise Data

Your integration engine stays in your data center. PHI never stored on OpenShare servers. Your data, your infrastructure, your control.

Outbound-Only Connections

The Gateway Plugin initiates outbound connections only. No inbound ports required. Your firewall stays closed to the outside world.

Signaling-Only Server

OpenShare coordinates connections but never sees or stores your data. We handle the handshake. You handle the data.

Two connection modes. Both encrypted.

Whether your connection is direct or relayed, your data stays encrypted end-to-end.

Preferred

Direct Connection

Fallback

TURN Relay

Architecture

Zero trust
by design.

Every layer of the OpenShare platform is built on the assumption that no network, device, or connection should be implicitly trusted. Security is enforced at every boundary.

Compliance details

No inbound ports

Gateway Plugin initiates all connections outbound to the OpenShare signaling server. Your firewall rules stay restrictive.

Session-based authentication

Every connection requires valid session tokens. No persistent credentials stored on the wire.

No data stored with OpenShare

Your integration engine data and PHI stay on your own infrastructure. OpenShare stores none of it and has no access to it.

Audit logging

All connection lifecycle events and administrative actions are logged for compliance review.

Built for regulated healthcare.

OpenShare is a secure healthcare integration platform designed for organizations handling protected health information. Taking us through a security review? Get in touch and we will walk your team through our controls, our policies, and where our responsibilities end and yours begin.

HIPAA-Ready

Designed for protected health information. Encryption, access controls, and audit logging built into every layer of the platform.

Business Associate terms

Business Associate terms are available for enterprise deployments, scoped to the control plane, data plane, and relay. Details on the compliance page, or email sales@openshare.health.

End-to-end encrypted in transit

Data is end-to-end encrypted with WebRTC DTLS as it moves between organizations. At rest, your integration engine data stays on your own infrastructure under your control, never stored by OpenShare.

On-Premise Data

Your integration engine stays in your data center. PHI never leaves your infrastructure. The Gateway Plugin connects it, without moving your data.

Frequently asked questions

OpenShare is designed for HIPAA compliance with end-to-end encryption (WebRTC DTLS), RBAC access controls, audit logging, and safeguards aligned to the HIPAA Security Rule. Business Associate terms are available for enterprise deployments; see our compliance page.

No. OpenShare acts as a signaling-only server in direct mode. It coordinates connections but never sees or stores your data. All data is encrypted end-to-end using WebRTC DTLS. In TURN relay fallback mode, data transits OpenShare infrastructure but remains end-to-end encrypted, OpenShare cannot read it.

No. The Gateway Plugin initiates all connections outbound. No inbound ports are required. Your firewall rules stay restrictive.

Your integration engine and all PHI stay on your infrastructure. OpenShare never stores your healthcare data. The platform connects to your on-premise servers without moving your data.

OpenShare falls back to a TURN relay. Traffic then transits OpenShare relay infrastructure, but it stays end-to-end encrypted the entire way, so OpenShare cannot decrypt or read it. For the strictest environments you can disable TURN entirely, which removes the relay path so traffic only ever flows directly between peers.

Access is governed by role-based access controls (RBAC) in the Console, so each user can only do what their role permits. Every peer connection is mutually authenticated: you approve each organization you exchange data with, and all activity is captured in audit logs. Combined with end-to-end encryption, that means access to your PHI is controlled by you, not by OpenShare.

Questions about security?

We take healthcare data security seriously and can walk you through the architecture end to end.