Architecture
Access is granted per request and per workload, every change is scanned before it merges, and audit evidence is collected continuously instead of assembled before each audit.
- Okta SSO with AWS IAM Identity Center and time-bound production access
- Private subnets and VPC endpoints for every service handling PHI
- Snyk, Trivy and Checkov checks in every pull request
- GuardDuty, Security Hub and CloudTrail routed to a 24/7 on-call rotation
- Vanta collecting control evidence from AWS, GitHub and Okta