The reason this evaluation usually takes six weeks.
Most workforce tools arrive claiming a compliance posture they can't evidence, needing a directory integration on day one, and wanting a data flow nobody scoped. Then somebody discovers it stores something it shouldn't and the review restarts. We would rather fail your evaluation on the first call than on the fourth.
- Vendors claiming to be "HIPAA certified" — a certification HHS does not issue.
- A SOC 2 logo that turns out to belong to a subprocessor, not the product.
- Tools that need SSO, SCIM and a directory sync before they do anything at all.
- Unclear scope: does it touch PHI or not, and who decided?
- Shadow IT — a unit adopts something for free and you find out at audit.
- Security questionnaires answered by a sales team who cannot see the code.
What an evaluation actually involves here.
Short, because the scope is narrow on purpose.
- Step 1Confirm the scope.
Adelo holds workforce operations data — schedules, hours, attendance, credentials, messages between staff, recognition. It is designed to exclude patient information; PHI should not be entered or uploaded, and the workflows give no reason to.
- Step 2Review access control.
Authentication runs on a managed provider. Authorization is role-based and least-privilege: charge, manager, HR and executive each resolve to a different scope. Units are isolated from one another — members of one unit cannot reach another's data.
- Step 3Review the honest gaps.
Adelo is not SOC 2 or HITRUST certified and has not completed an independent third-party security assessment. Availability and backup commitments, a formal vulnerability management program and third-party assessment are on the roadmap, not in place. We publish that rather than bury it.
- Step 4Decide on integration — or don't.
Nothing needs to be integrated for Adelo to work. There is no directory sync to stand up, no agent to deploy, no on-prem component. HR, identity and scheduling-source integrations are roadmap items today; Enterprise includes integration planning and data-import support now.
- Step 5Ask us for the documentation.
Security documentation is available on request on every plan, and vulnerability reports go to security@getadelo.com. If your questionnaire has a question we answer badly, we would rather know.
How it behaves — the same on every plan.
Security posture does not vary by tier. A free unit gets the same isolation and the same access model as an enterprise one.
Access & identity
- Secure sign-in on a managed authentication providerFree
- Role-based, least-privilege authorizationFree
- Unit-level data isolationFree
- Scoped, controlled data accessFree
- Advanced roles and permissionsPremium
- Centralized administrationEnterprise
Data & scope
- PHI out of scope by design — do not enter itFree
- Data minimization — only what the workflow needsFree
- Managed cloud infrastructure with encryptionFree
- No replacement of, or write-back to, your HCMFree
- Nothing to install — runs in any phone browserFree
- Integration planning and data-import supportEnterprise
What we have not earned yet
- SOC 2 — not certified
- HITRUST — not certified
- Independent third-party assessment — not completed
- Formal vulnerability management program — planned
- Documented availability and backup commitments — planned
- "HIPAA certified" — no such certification exists
Why we publish the gaps.
A security page that lists only strengths tells a reviewer nothing, because every vendor's page lists only strengths. The useful signal is whether a company will tell you what it hasn't done before you find out yourself. That is the same reason there is no "HIPAA certified" badge on this site — HHS does not issue one, and any vendor displaying it is telling you something about how they handle claims generally.
- Security documentation available on request, on every plan
- Vulnerability disclosure to security@getadelo.com
- Roadmap items are labeled as roadmap, with no implied date we can't meet
- If a shadow-IT free unit already exists in your organization, we will tell you