Trust

Security and Data Stewardship

Last updated July 2026

CodaHx audits employer health claims, which means customers trust us with sensitive data: claim lines, service dates, provider names, payment amounts. Some of it is protected health information (PHI).

Our operating principle is simple: member-level data stays inside the product, access is scoped to your workspace, and anything that leaves is deliberate and logged. This page describes the controls that exist in the product today, in plain terms.

Access and Authentication

There is no open signup. CodaHx accounts are invite-only: a workspace admin sends an invite, and only the invited email can create an account. Invites expire if they are not used.

  • Sign in with Google or with email and password.
  • Two-factor authentication with an authenticator app is available on every account and can be turned on in settings.
  • Sign-in and other authentication endpoints are rate limited.

Who Can See What

Every customer gets its own workspace, and requests to the API are checked against your membership in that workspace. You only see data for workspaces you belong to.

Workspaces have three roles (viewer, editor, and admin), and the server enforces a minimum role for sensitive actions.

Exporting Member-Level Data

Member-level claim detail does not leave the product casually. When someone exports it (for example a findings CSV or a review packet for your administrator), the product first walks them through a release review: they pick the purpose and the recipient, then see field-by-field guidance on what each exported column can reveal, with recommended handling for the sensitive ones. The export proceeds only after they confirm the review.

Every export is then written to an audit ledger: who exported, when, in what format, how many records, and which fields were included along with their sensitivity classification. That ledger is visible inside the workspace, so your team can see the full export history.

Encryption

Data moves between your browser and CodaHx over HTTPS, so it is encrypted in transit. At rest, it is stored with our database provider in managed Postgres that encrypts stored data.

Your Data in the Product

The claims files you share become structured records inside your workspace: claim lines, audit findings, and reports. They stay scoped to that workspace.

We do not sell, rent, or lease your data. Our privacy policy covers this in more detail, including how we work with the vendors that help us run the service.

Questions

If you are evaluating CodaHx and want to go deeper on any of this, ask. Write to contact@codahx.com or reach out through the contact page and we will walk you through the details.