Leading the Way
in Security & Compliance

Protecting sensitive information isn’t just a priority—it’s foundational to everything we do. From preventing data breaches and account hijacking to securing API’s and mitigating insider threats, we proactively safeguard data integrity. We support corporate compliance, reinforcing trust and resilience at every level.

Our Certifications and
Compliance Standards

Commence maintains a broad set of security, privacy, and compliance certifications that reinforce the protection of sensitive data across healthcare and government programs. These standards reflect our commitment to trusted systems, responsible data stewardship, and continuous improvement.

Amazon Web Services’ (AWS) image

AWS

Commence’s infrastructure is hosted within the highly secure Amazon Web Services (AWS) cloud environment. AWS provides enterprise-grade physical and network security controls that support the protection, availability, and resilience of customer data.

California Consumer Privacy Act image

CCPA

Commence supports compliance with the California Consumer Privacy Act (CCPA) and acts as a processor of customer data. Our systems and practices help organizations meet CCPA requirements for protecting consumer privacy and managing personal data responsibly.

Department of Defense (DoD) Image

DoD SRG Levels 2&4

Commence infrastructure aligns with the Department of Defense (DoD) Cloud Computing Security Requirements Guide (SRG) at Levels 2 and 4. This alignment supports secure cloud environments for government workloads and enables service to DoD customers.

Federal Information Security Management Icon

FISMA

Commence supports compliance with the Federal Information Security Management Act (FISMA), which requires federal information systems to implement comprehensive security programs. These controls help protect government data and maintain secure system operations.

General Data Protection Regulation image

GDPR

Commence supports organizations in meeting the requirements of the General Data Protection Regulation (GDPR). GDPR establishes strict standards for protecting personal data and gives individuals greater control over how their information is used.

GLBA Compliant Image

GLBA

Compliant with GLBA standards for protecting the privacy of customer financial information through encryption before transmission, during transmission, and while at rest. These safeguards help protect data from physical threats and unauthorized access while supporting secure financial information management.

Health Insurance Portability and Accountability Act Image

HIPAA

Commence supports compliance with the Health Insurance Portability and Accountability Act (HIPAA), which establishes national standards for protecting sensitive patient health information. Our systems and processes are designed to safeguard protected health information and support secure healthcare operations.

r2 Hitrust badge

HITRUST r2

The platform supporting Commence’s healthcare data solutions has earned HITRUST r2 Certification, demonstrating that it meets rigorous standards for cybersecurity and information protection. This certification helps ensure sensitive healthcare data is protected while supporting trusted, secure operations across complex health programs.

International Organization for Standardization certified Image

ISO/IEC 27001 & 27017

Commence is certified to ISO/IEC 27001 for Information Security Management and ISO/IEC 27017 for Cloud Security. These internationally recognized standards validate structured security controls designed to protect sensitive information in cloud environments.

ISO 9001 Company image

ISO 9001

Commence is certified to ISO 9001 for quality management systems. This certification reflects our commitment to consistent processes, operational excellence, and continuous improvement across our services and solutions.

Payment Card Industry Data Security Standard

PCI DSS Level 1

Commence supports compliance with the Payment Card Industry Data Security Standard (PCI DSS Level 1). These controls help ensure credit card information is processed, stored, and transmitted securely.

SOC 2 compliant badge

SOC 2

Commence maintains SOC 2 compliance, demonstrating adherence to rigorous standards for security, availability, processing integrity, confidentiality, and privacy. This certification validates our commitment to protecting customer data through independently assessed controls.

Accredited for Health Utilization Management Image

URAC

Commence holds URAC accreditation for Health Utilization Management, reflecting a commitment to healthcare quality, patient safety, and accountable clinical review processes.

Virginia Values Veterans logo

Virginia Values Veterans

Commence is certified through the Virginia Values Veterans (V3) Program. This certification recognizes organizations that demonstrate a commitment to recruiting, hiring, and supporting veterans in the workforce.

Your Data & Trust, Protected

Securing your information is our top priority. Learn more about how we safeguard data integrity, ensure compliance, and uphold the highest security standards.

Woman Doctor