This document is part of the CompleteRx proposal. Access is granted automatically from the main proposal.
This document is intended for IT, security, and compliance stakeholders who need technical assurance before approving the Peopletree Group platform for use within CompleteRx.
The Peopletree Group platform is built on enterprise-grade infrastructure with a security-first architecture. The following badges summarise the key security and compliance posture.
The platform is hosted on enterprise cloud infrastructure with a layered security model covering infrastructure, application, data, and AI processing.
The platform is hosted on AWS with multi-region redundancy. All infrastructure is managed by Peopletree Group's technical team and subject to annual third-party security audits.
Access to the platform is controlled through role-based access control (RBAC) with multi-factor authentication (MFA) required for all HR administrator accounts.
All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Assessment data and personal information are stored in isolated, access-controlled environments.
The TAILA AI coaching assistant processes assessment data within the Peopletree Group environment. No assessment data is sent to external AI providers without explicit consent.
The platform includes real-time monitoring, anomaly detection, and a formal incident response process. All access events are logged and available for audit review.
The platform is SOC 2 Type II certified, covering Security, Availability, and Confidentiality trust service criteria. Certification is maintained through annual third-party audits.
The following table clarifies the roles and responsibilities for data ownership, access, and security between CompleteRx and Peopletree Group.
| Area | CompleteRx Responsibility | Peopletree Group Responsibility |
|---|---|---|
| Data Ownership | Owns all participant data and assessment results | Processes data on behalf of CompleteRx as data processor |
| Access Control | Nominates HR administrator and approves participant access | Provisions accounts and enforces RBAC policies |
| Data Retention | Defines retention period (default: 3 years) | Applies retention policy and manages secure deletion |
| Incident Response | Notified within 24 hours of any security incident | Leads incident response and remediation |
| Compliance | Responsible for internal compliance and participant consent | Maintains SOC 2 certification and platform compliance |
For technical or security questions about the Peopletree Group platform, please contact the technical team directly. Initial enquiries can be directed through the project team.
Technical contact: rob@peopletreegroup.com
Rob Heymann, Head of Technology, Peopletree Group