The problem

The reason this evaluation usually takes six weeks.

Most workforce tools arrive claiming a compliance posture they can't evidence, needing a directory integration on day one, and wanting a data flow nobody scoped. Then somebody discovers it stores something it shouldn't and the review restarts. We would rather fail your evaluation on the first call than on the fourth.

  • Vendors claiming to be "HIPAA certified" — a certification HHS does not issue.
  • A SOC 2 logo that turns out to belong to a subprocessor, not the product.
  • Tools that need SSO, SCIM and a directory sync before they do anything at all.
  • Unclear scope: does it touch PHI or not, and who decided?
  • Shadow IT — a unit adopts something for free and you find out at audit.
  • Security questionnaires answered by a sales team who cannot see the code.
A day with Adelo

What an evaluation actually involves here.

Short, because the scope is narrow on purpose.

  1. Step 1
    Confirm the scope.

    Adelo holds workforce operations data — schedules, hours, attendance, credentials, messages between staff, recognition. It is designed to exclude patient information; PHI should not be entered or uploaded, and the workflows give no reason to.

  2. Step 2
    Review access control.

    Authentication runs on a managed provider. Authorization is role-based and least-privilege: charge, manager, HR and executive each resolve to a different scope. Units are isolated from one another — members of one unit cannot reach another's data.

  3. Step 3
    Review the honest gaps.

    Adelo is not SOC 2 or HITRUST certified and has not completed an independent third-party security assessment. Availability and backup commitments, a formal vulnerability management program and third-party assessment are on the roadmap, not in place. We publish that rather than bury it.

  4. Step 4
    Decide on integration — or don't.

    Nothing needs to be integrated for Adelo to work. There is no directory sync to stand up, no agent to deploy, no on-prem component. HR, identity and scheduling-source integrations are roadmap items today; Enterprise includes integration planning and data-import support now.

  5. Step 5
    Ask us for the documentation.

    Security documentation is available on request on every plan, and vulnerability reports go to security@getadelo.com. If your questionnaire has a question we answer badly, we would rather know.

What you get

How it behaves — the same on every plan.

Security posture does not vary by tier. A free unit gets the same isolation and the same access model as an enterprise one.

Access & identity

  • Secure sign-in on a managed authentication providerFree
  • Role-based, least-privilege authorizationFree
  • Unit-level data isolationFree
  • Scoped, controlled data accessFree
  • Advanced roles and permissionsPremium
  • Centralized administrationEnterprise

Data & scope

  • PHI out of scope by design — do not enter itFree
  • Data minimization — only what the workflow needsFree
  • Managed cloud infrastructure with encryptionFree
  • No replacement of, or write-back to, your HCMFree
  • Nothing to install — runs in any phone browserFree
  • Integration planning and data-import supportEnterprise

What we have not earned yet

  • SOC 2 — not certified
  • HITRUST — not certified
  • Independent third-party assessment — not completed
  • Formal vulnerability management program — planned
  • Documented availability and backup commitments — planned
  • "HIPAA certified" — no such certification exists

Why we publish the gaps.

A security page that lists only strengths tells a reviewer nothing, because every vendor's page lists only strengths. The useful signal is whether a company will tell you what it hasn't done before you find out yourself. That is the same reason there is no "HIPAA certified" badge on this site — HHS does not issue one, and any vendor displaying it is telling you something about how they handle claims generally.

  • Security documentation available on request, on every plan
  • Vulnerability disclosure to security@getadelo.com
  • Roadmap items are labeled as roadmap, with no implied date we can't meet
  • If a shadow-IT free unit already exists in your organization, we will tell you