Your partner or customer needs a signed Business Associate Agreement before patient data touches production. Your BAA is with AWS directly through your own account. You can execute immediately — no enterprise sales call required. Hand it to your compliance officer or security lead today and unblock your audit timeline.
Convox runs entirely inside your own AWS account using Bring Your Own Cloud (BYOC). Your PHI stays in infrastructure you own and control — not a shared PaaS environment you're renting from a vendor. That's the data ownership story your compliance officer needs for your next HIPAA audit, and the architectural control your CTO actually wants.
Define your HIPAA workload once in a convox.yml — services, databases, environment secrets, network isolation — and run `convox deploy` to ship to a compliant, encrypted, VPC-isolated environment on AWS. No custom Terraform modules. No DevOps contractor. No six-week onboarding. Your engineering team operates at product velocity from day one.
Convox provisions encrypted RDS and EFS storage, private VPC networking, TLS termination, and CloudTrail-compatible audit logging out of the box. The controls your auditor will ask about are on by default — not a checklist you configure manually. Your security lead gets a defensible infrastructure posture without writing a single line of Terraform.
Aptible charges a significant premium for compliance-first branding and a managed environment your data lives in. Convox deploys into your AWS account where your BAA with AWS applies, the same encryption and access controls, and a deployment platform your developers actually enjoy — deployed into AWS infrastructure you already own. Keep the compliance posture. Stop paying the Aptible tax.
Convox provides HIPAA-aligned architecture guides and configuration references that map directly to what your compliance officer needs to document for an audit or customer security review. When the compliance stakeholder is the one driving this evaluation, we make sure they have the artifacts they need — not just the engineers.