Security-First Architecture

Security is engineered into every layer.

The GMA MyCompass System uses a defense-in-depth architecture spanning identity, applications, managed devices, sensitive information, cloud infrastructure, approved integrations, secure engineering, AI processing, and operational response. Access remains permission-based, every environment remains governed, and oversight continues throughout authorized use.

Purpose-built for high-responsibility support environments where privacy, continuity, and controlled access are not optional.

Purpose-Built · Permission-Based · Continuously Governed

Zero-Trust Principles

Nothing receives implicit trust.

No person, device, application, integration, environment, automated process, or AI capability receives unrestricted authority simply because it is known to GMA or already operates within MyCompass. Identity, authorization, context, integrity, sensitivity, and responsibility remain subject to verification and control.

Every request must earn access. Every permission must have a purpose. Every meaningful action must remain accountable.

Verify Explicitly

Identity, role, context, device posture, application integrity, and operational need remain subject to validation.

Limit Access

Permissions are restricted according to responsibility, consent, purpose, and least-necessary access.

Reevaluate Continuously

Previously approved identities, devices, sessions, integrations, and workflows are not treated as permanently trustworthy.

Human Authority Remains in Control

Automation can support verification, prioritization, restriction, and response, while material authority remains governed by authorized people.

Defense in Depth

A coordinated security stack across every boundary.

MyCompass layers identity, device, application, information, cloud, integration, monitoring, and response controls so that no single safeguard carries the entire burden. Each layer reinforces the others within one governed security environment.

Protection is layered. Trust remains limited. Oversight continues across the entire system.

Zero-trust principles and continuous governance apply throughout all six layers of this security stack.

Zero-Trust Principles
01
Identity & Access Control

Access must be explicitly earned.

Identity, authorization, role, responsibility, and operational need are evaluated before access is permitted and throughout authorized use.

Multifactor Authentication · Role-Based Access · Controlled Administration

02
Device & Application Integrity

Protection continues at the point of use.

Managed-device controls, application-integrity verification, secure configuration, and mobile threat defenses help protect the environments through which people access MyCompass.

Managed Devices · Application Integrity · Mobile Threat Defense

03
Data Protection & Privacy

Protection begins the moment information enters the environment.

Information is protected during transmission, encrypted upon entry into the GMA-controlled environment, and governed throughout authorized storage, processing, and use.

Encryption in Transit · Encryption Upon Entry · Sensitive-Data Monitoring

04
Cloud, Application & Network Defense

Multiple controls protect the digital environment.

Cloud infrastructure, applications, APIs, network activity, and public-facing services remain protected through coordinated application, traffic, access, and threat-defense controls. Built on AWS cloud infrastructure.

Cloud Security · Application & API Defense · Web & Network Controls

05
Integration & Third-Party Oversight

Vendor approval does not create unrestricted trust.

Approved integrations remain permissioned, contractually governed where appropriate, logged, monitored, and subject to GMA’s own security and privacy controls.

Integration Review · Limited Access · Appropriate BAAs

06
Continuous Monitoring & Response

Security awareness continues after deployment.

Security events, application activity, sensitive-data findings, device status, availability, and operational concerns are evaluated to support risk prioritization, investigation, authorized response, and continued improvement.

Continuous Monitoring · Risk Orchestration · Incident Response

Continuous Governance & Oversight
The Foundation Beneath Every Layer

Secure engineering and healthcare governance support the entire stack.

Structured Code Review · Environment Separation · Authorized Penetration Testing

Controlled Change Management · Healthcare Privacy Governance · Continuity & Incident Readiness

Secure development, controlled releases, authorized adversarial testing, contractual safeguards, documented policies, and continued improvement reinforce every layer of the operating stack.

One governed security environment.

Multiple protection layers. No single control carries the burden.

Zero-trust principles and continuous governance extend across the entire stack.

Security Operations · The Stack in Operation

Security signals become governed action.

The MyCompass security environment brings together signals from identity, applications, managed devices, sensitive information, cloud infrastructure, network activity, approved integrations, system availability, and engineering workflows. Governed orchestration helps enrich findings, establish context, prioritize meaningful concerns, and support timely investigation and authorized response.

Signals are correlated. Risk is contextualized. Response remains governed.

Continuous Awareness
Governed Orchestration
Authorized Response

Policy, authorization, and human oversight apply across the complete Security Operations Engine, from signal collection through orchestration, response, and improvement.

Policy · Authorization · Human Oversight

Every stage remains subject to approved authority, documented responsibility, and human governance.

Signals Across the Environment

Awareness begins across every security domain.

Security and operational signals are collected from authorized sources throughout the MyCompass environment so meaningful conditions can be evaluated together rather than in isolation.

Identity · Managed Devices · Applications · Sensitive Information · Cloud & Network · Integrations · Availability · Engineering Activity

Governed Risk Orchestration

Context determines what requires attention.

Governed workflows can enrich findings, correlate related activity, apply appropriate risk context, prioritize concerns, and route relevant information without granting automation unrestricted authority.

Enrich · Correlate · Contextualize · Prioritize · Route

Authorized Response & Improvement

Human-governed action strengthens the environment.

Authorized personnel investigate, contain, document, recover, and apply lessons from security events, testing, findings, and operational concerns to support continued hardening and control improvement.

Investigate · Contain · Recover · Document · Retest · Harden

Automation accelerates awareness and approved response.

Human authority remains in control.

Environmental Security

Every environment remains governed.

Security controls extend across the complete MyCompass software lifecycle. Development, testing, staging, and production remain separated and governed through controlled access, protected configuration, traceable change, structured testing, monitoring, and authorized promotion.

No environment is treated as an acceptable weak point.

The path to production is protected with the same seriousness as production itself.

Consistent Security Expectations Across the Software Lifecycle

Access Control · Environment Separation · Protected Configuration · Traceability · Testing · Authorized Promotion · Monitoring

 
01 — Development

Security begins where the system is built.

Source access, engineering activity, dependencies, configurations, and proposed changes remain subject to controlled access, secure-development practices, review, and documented accountability.

Controlled Source Access · Secure Development · Dependency Review

02 — Testing

Changes are evaluated before moving forward.

Automated and manual testing help identify defects, regressions, unexpected behavior, configuration concerns, and security risks before a change advances.

Automated Testing · Manual Validation · Regression & Risk Review

03 — Staging

Release readiness is verified within a separated environment.

Staging supports configuration validation, integration assurance, release review, and authorized approval before production promotion.

Environment Separation · Configuration Validation · Authorized Approval

04 — Production

Deployment does not end oversight.

Production access, deployments, system health, security activity, and operational conditions remain controlled, monitored, documented, and subject to incident readiness.

Controlled Deployment · Continuous Oversight · Incident Readiness

Changes must earn their way forward.

A successful build, automated test, or previously approved change is not by itself permission to enter production. Advancement requires appropriate review, validation, traceability, and authorized approval.

No automated system or AI agent may bypass required review and authorized production approval.

Environment Separation

Each environment maintains a defined boundary according to purpose, access, information sensitivity, and operational responsibility.

Protected Configuration

Configurations, dependencies, credentials, integrations, and infrastructure changes remain governed alongside source code.

Traceable Change

Relevant changes, reviews, testing, approvals, promotions, and releases remain documented and attributable.

Continuous Assurance

Testing findings, authorized assurance activities, operational events, security concerns, and changing risks contribute to continued hardening.

Security remains part of the lifecycle before, during, and after every release.
Secure Engineering & Assurance

The system is tested against more than expected behavior.

MyCompass combines structured engineering review, systems-assurance testing, authorized adversarial validation, and documented remediation to identify weaknesses, unexpected behavior, and operational risk before they become accepted conditions. Findings are prioritized, corrected, and tested again as appropriate.

Approval is not the end of assurance.

Controls are challenged. Findings are addressed. Improvements continue.

Documented · Traceable · Risk-Informed · Human-Governed

Testing activity, findings, remediation decisions, and validation remain subject to authorized responsibility and documented accountability.

Engineering Assurance

Expected behavior is verified. Unexpected behavior is investigated.

Code, configurations, integrations, dependencies, and system behavior undergo structured human review and assurance testing for defects, regressions, unexpected outcomes, misuse conditions, and security concerns.

Structured Human Review · Systems-Assurance Testing · Regression Validation · Unexpected-Behavior Review

Authorized Adversarial Validation

Safeguards are actively challenged.

GMA performs ongoing authorized penetration testing and adversarial security validation against its own environment to identify weaknesses, test assumptions, and evaluate how safeguards behave under realistic challenge.

Authorized Penetration Testing · Vulnerability Validation · Adversarial Scenarios · Control Effectiveness Review

Remediation & Continued Hardening

Findings become measurable improvement.

Findings from assurance testing, adversarial validation, security events, operational experience, software changes, and emerging risks are documented, prioritized, remediated, and tested again as appropriate.

Document · Prioritize · Remediate · Retest · Harden

Review → Challenge → Remediate → Retest → Improve

A finding is not considered resolved merely because a change was made. Remediation is validated according to its risk, scope, and operational impact.

Security assurance does not end when a change is approved.

Controls are challenged, findings are addressed, and improvements continue.

The objective is not to claim that weaknesses can never exist. It is to identify, understand, remediate, and learn from them before they become accepted risk.

Protected Data Ingestion

Information enters MyCompass through a governed security boundary.

Information received from approved devices, applications, and third-party integrations is protected during transmission and encrypted upon entry into the GMA-controlled environment. From that point forward, it remains subject to GMA’s access, logging, monitoring, privacy, retention, and authorized-use requirements.

Vendor approval does not replace GMA security.

An approved source does not receive unrestricted trust, and incoming information does not bypass GMA’s own security and privacy controls.

GMA Security & Privacy Controls

Access Control · Encryption · Logging · Sensitive-Information Monitoring · Retention · Authorized Use

01 — Protected in Transit

Protection begins before information arrives.

Approved connections and protected transmission help safeguard information as it moves toward the GMA-controlled environment.

02 — Encrypted Upon Entry

Information enters a controlled security boundary.

Upon entry into the GMA environment, information is encrypted before authorized storage, processing, or downstream use.

03 — Governed Throughout Use

Protection continues after ingestion.

Access, logging, monitoring, retention, privacy requirements, and authorized-use controls continue throughout the information lifecycle.

Protection continues beyond ingestion.

Once information crosses the GMA security boundary, it remains governed throughout every authorized workflow.

Additional Privacy Controls Before AI Processing

When information is authorized for AI-assisted support, identity is minimized, context is limited, access remains permission-based, and human authority remains central.

Only the context appropriate to the authorized purpose proceeds into the governed AI workflow.

Secure AI by Design

Nora is governed before, during, and after model processing.

Nora Caregiver Intelligence uses enterprise foundation models through Amazon Bedrock within a controlled GMA security and privacy workflow. Information is limited according to the authorized purpose, direct identifiers are removed or replaced where appropriate before model processing, access remains permission-based, outputs remain governed, and meaningful concerns may be routed to authorized caregivers while human authority remains in control.

Protecting the person’s information is part of Nora’s architecture. It is not a secondary consideration.

Your Information Is Treated as a Responsibility.

Nora is designed to use only the context needed for the authorized task, within defined privacy, access, safety, and human-oversight boundaries.

Security, privacy, permission, and human oversight apply across all six stages of Nora’s AI-processing workflow, from authorized purpose through human decision.

Security, Privacy, Permission & Human Oversight

Purpose Limitation · Identity Minimization · Access Control · Guarded Output · Human Oversight

AI involvement does not expand access, remove accountability, or replace human authority.

01 — Authorized Purpose

The task determines what information may be used.

Nora operates only for an authorized support purpose. Role, consent, operational need, and permitted use help determine what information may be considered.

Purpose-Limited · Role-Aware · Consent-Governed

02 — Limited Context

Nora receives only the context appropriate to the task.

Information is limited according to the authorized interaction, support need, requesting role, and permitted purpose rather than providing unrestricted access to all available information.

Context Limited · Need-Based · No Unrestricted Access

03 — Identity Minimization

Unnecessary identity exposure is reduced.

Direct identifiers are removed or replaced where appropriate before authorized context is submitted for model processing.

Identity Minimized · Privacy-Preserving Preparation

04 — Governed Model Processing

The model operates within a controlled boundary.

Authorized and prepared context is processed through enterprise foundation models within a workflow governed by GMA security, privacy, access, and information-handling requirements. The model is one component within Nora’s security architecture — not the authority controlling it.

05 — Guarded Output

Intelligence operates within defined boundaries.

Nora’s responses remain subject to safety, privacy, role, permission, and human-oversight requirements.

Safety Boundaries · Permission-Based Output

06 — Governed Escalation

Meaningful concerns can reach an authorized person.

When appropriate under an approved support pathway, relevant information may be routed to an authorized caregiver or support team according to role, permission, consent, need, and the circumstances involved. Nora may help identify, organize, and escalate concerns. Authorized people remain responsible for interpretation, judgment, and action.

These principles describe the safeguards surrounding Nora. They are not a representation of GMA’s internal processing architecture.

Authorized Purpose · Limited Context · Identity Minimization · Governed Processing · Guarded Output · Human Authority
Continued AI Assurance

Nora’s safeguards remain subject to testing and refinement.

Security concerns, engineering changes, identified risks, operational findings, and authorized assurance activities inform continued review and strengthening of Nora’s protections.

Test · Review · Refine · Strengthen

Approval to operate does not end assurance.

Additional technical information may be made available through approved security reviews, procurement processes, or controlled discussions.

Your information is not exposed to an unrestricted AI workflow.

Nora uses authorized, purpose-limited, identity-minimized context within a governed workflow. Access remains restricted, outputs remain permission-based, and the person’s privacy, consent, and support needs remain central.

Nora’s intelligence is designed to support the person, not expose them.

Healthcare Privacy Governance

Privacy obligations are translated into operating controls.

GMA reinforces technical safeguards through documented privacy practices, appropriate contractual protections, controlled access, accountable information handling, incident readiness, continuity planning, and evidence that supports oversight.

Compliance is not treated as a document stored on a shelf.

It is reflected in how access, information, vendors, incidents, responsibilities, and operational decisions are governed.

Documented · Contractually Supported · Accountable · Evidence-Informed

Technical safeguards, contractual obligations, assigned responsibilities, and operational evidence work together within one governance program.

Contractual Protection

Privacy obligations extend beyond GMA.

GMA maintains appropriate Business Associate Agreements and other applicable contractual safeguards with relevant vendors and service providers that create, receive, maintain, or transmit protected health information on GMA’s behalf.

Contracts define permitted information use, security responsibilities, safeguards, and accountability.

Policy & Responsibility

Expectations are documented and assigned.

Privacy, access, information handling, incident response, continuity, change management, and security practices establish defined responsibilities and repeatable operational expectations.

Governance requires more than written policy. Responsibilities must be understood, applied, and accountable.

Oversight & Evidence

Meaningful activity remains accountable.

Access, changes, security events, integration activity, reviews, and operational decisions generate evidence that can support investigation, governance, accountability, and continued improvement.

Controls must be capable of producing meaningful evidence, not merely existing in theory.

Incident & Continuity Governance

Privacy responsibilities continue during disruption.

Documented response, communication, recovery, continuity, and improvement practices help guide responsible action when security events, privacy concerns, service interruptions, or operational disruptions occur.

A disruption does not suspend accountability.

Designed for HIPAA-Aligned Operations

Technical safeguards and privacy governance operate together.

Technical Safeguards · Appropriate Contractual Protections · Documented Policies · Accountable Access · Incident Readiness · Governance Evidence

These disciplines work together to support responsible handling of protected information throughout authorized operations.

Our Security Commitment

Security carries a human consequence.

We protect the system because people rely on it.

MyCompass supports people whose privacy, safety, independence, and continuity of support can be affected by the integrity of the systems surrounding them. That responsibility is why GMA treats security as an operating obligation — not a feature added later or a minimum requirement checked once.

Every layer of protection, every controlled permission, every engineering review, every monitored event, and every safeguard around Nora exists for the same reason: people, families, caregivers, and organizations place real trust in the system.

Managed Device & Digital Safety

The device operates inside a managed security boundary.

MyCompass extends protection to the endpoint people use every day. Device configuration, applications, access, mobile threats, connectivity, content safeguards, and ongoing oversight remain part of one coordinated security environment configured around the person.

A device does not receive unrestricted trust merely because it belongs to the MyCompass environment.

Its configuration, applications, connectivity, security posture, and permitted use remain governed according to the authorized purpose, the person’s preferences and consent, and the responsibilities of approved supporters.

Managed · Protected · Personalized · Continuously Overseen

The device remains part of the broader MyCompass security environment throughout authorized use.

Continuous Device Oversight
01
Managed Endpoint Governance

The device begins from a controlled foundation.

Supported devices can be configured, maintained, and overseen within a managed environment so important security, access, and operational settings are not left entirely to chance.

Managed Configuration · Controlled Settings · Device-Posture Awareness

02
Application & Access Governance

Access is configured around the person and the purpose.

Applications, capabilities, content, and device access can be configured according to the person’s preferences, consent, support plan, relevant risks, and authorized needs.

Approved Applications · Purpose-Based Access · Personalized Configuration

03
Mobile Threat & Connectivity Protection

Protection continues across applications, messages, and connections.

Mobile threat defenses, application-integrity awareness, malicious-link protection, device-posture signals, protected connectivity, and encrypted communications can help reduce exposure to suspicious applications, unsafe connections, phishing, smishing, and other evolving digital risks.

Mobile Threat Defense · Malicious-Link Protection · Protected Connectivity

04
Personalized Digital Safety

Safeguards reflect the individual, not a generic restriction profile.

Granular content controls and digital-safety safeguards can help reduce exposure to malicious, exploitative, inappropriate, unsafe, or individually triggering material while respecting the person’s preferences, consent, independence, and support needs.

Granular Content Controls · Individualized Safeguards · Human Oversight

Person-Centered Governance

Protection should strengthen independence, not replace it.

Security controls can help reduce digital risk and support safer access without removing the person’s voice from decisions about their technology. Safeguards should reflect the individual’s preferences, consent, support needs, and right to participate in decisions affecting their digital environment.

Managed protection. Personalized access. Human judgment. The person remains central.

Operational Resilience

Resilience is designed into how MyCompass responds to disruption.

MyCompass combines continuous awareness, fail-safe operating principles, approved fallback pathways, controlled rollback, regional recovery readiness, protected backups, documented response procedures, and recovery validation to help preserve responsible operation through incidents, outages, unstable changes, and changing conditions.

Continuity is not one backup. It is a coordinated operating discipline.

The objective is to recognize disruption, limit impact, preserve the safest available operation, recover deliberately, and verify that restoration is working as intended.

Monitored · Documented · Authorized · Tested · Human-Governed

Fallback, rollback, recovery, and continuity actions remain subject to approved responsibility, documented processes, and authorized human oversight.

01 — Continuous Awareness

Disruption must be recognized before it can be managed.

Service health, availability, connectivity, device status, security activity, and meaningful operational conditions are monitored so concerns can be identified, evaluated, and routed for authorized response.

Service Health · Connectivity Awareness · Operational Visibility

02 — Fail-Safe & Graceful Response

The system is designed to respond responsibly when conditions change.

Where appropriate, fail-safe behavior and graceful degradation help limit unnecessary impact, preserve safer available functions, and prevent unstable conditions from being treated as normal operation.

Fail-Safe Behavior · Impact Limitation · Graceful Degradation

03 — Fallback & Regional Continuity

Continuity does not depend on one operating path.

Approved fallback pathways, protected recovery resources, and regional standby capabilities help support continued or restored operation when a primary service, dependency, connection, or environment becomes unavailable.

Approved Fallback · Regional Standby · Recovery Readiness

04 — Controlled Rollback & Recovery

Recovery includes knowing when to move backward.

When a software, configuration, infrastructure, or integration change creates unacceptable instability or risk, approved rollback and restoration processes help return the environment toward a known, governed state.

Forward progress is not preserved at the expense of safe and stable operation.

Controlled Rollback · Protected Backups · Documented Recovery

Recovery is not complete until it is verified.

Restored services, recovered information, connectivity, system behavior, and operational conditions are evaluated before recovery is considered complete. Findings from incidents, testing, and exercises inform continued improvement.

Restoration must be confirmed, not assumed.

Recovery Validation · Readiness Testing · Continued Improvement

Awareness · Containment · Safe Continuation · Recovery · Validation

These principles describe GMA’s resilience disciplines and do not represent the internal recovery architecture.

Continuity of Support

Recovery decisions are made with the people relying on MyCompass in mind.

Availability, connectivity, system behavior, information protection, and caregiver communication can all affect continuity of support. GMA’s resilience practices are designed to help reduce disruption, preserve responsible operation, and support informed human response when conditions become difficult.

The goal is not to pretend disruption cannot happen. The goal is to be prepared when it does.

Documented Response Authorized Decision-Making Communication & Coordination
Recovery Procedures Business Continuity Post-Incident Improvement

Documented responsibilities and continuity practices help guide investigation, containment, communication, restoration, and improvement during security events and operational disruption.

Controlled Security Assurance

Detailed assurance. Shared responsibly.

The public Security page explains GMA’s operating principles without exposing the implementation blueprint. Organizations evaluating MyCompass may request access to selected security, governance, procurement, and assurance materials according to their role and legitimate review needs.

Transparency does not require unrestricted disclosure.

GMA provides meaningful evidence while protecting client security, confidential controls, proprietary architecture, and information that could increase operational risk if published openly.

Public Overview

Security principles available to every visitor.

The public Security page explains GMA’s security philosophy, governance model, person-centered safeguards, resilience practices, and high-level control domains without publishing the implementation blueprint.

No Request Required

Security Principles · Governance Model · Person-Centered Protection

Requested Access

Selected security and assurance materials for legitimate evaluation.

Organizations, case-management teams, providers, procurement professionals, security teams, and other legitimate evaluators may request access to selected GMA security, governance, infrastructure, and assurance materials relevant to their review.

Access Provided After Request Review

Security-First Architecture · Critical Infrastructure · Operational Resilience · Managed Infrastructure · Secure AI Governance · Healthcare Privacy · Operational Trust

Primary Resource Pathway

Request Security Materials

Tell us what you are evaluating, and GMA will provide the materials appropriate to your role and review needs.

Controlled Review

Deeper assurance for authorized security and procurement review.

When an evaluation requires implementation evidence, formal procurement support, questionnaires, demonstrations, or greater technical depth, GMA may provide a controlled review appropriate to the requester’s role, purpose, and confidentiality requirements.

Scope, Purpose & Confidentiality Reviewed First

Control Evidence · Procurement Questions · Security Questionnaires · Authorized Technical Discussion · Confidential Materials

Request a Security Review

Some implementation details may require an appropriate confidentiality agreement or other controlled-review process.

Security, Infrastructure & Operational Trust

Security Architecture · Critical Infrastructure · Operational Resilience · Healthcare Privacy

Secure AI Governance · Managed Infrastructure · Managed Device Security · Procurement Assurance

One collection within a growing library of GMA research, security assurance, and person-centered technology insights.

Explore GMA Research & Insights →

Browse public topics and request gated resources across technology, care, accessibility, preparedness, provider practice, and population-specific support.

Access is matched to purpose, role, and sensitivity.

Materials may be provided through gated access, qualified professional review, or a controlled confidentiality process according to the nature of the request and the sensitivity of the information.

Evidence for the right people. Protection for everyone relying on the system.

The Standard Is Personal

We build security with the standard we would expect for someone we love.

Every person using MyCompass is someone’s parent, child, sibling, family member, friend, or person entrusted to care. Their privacy, dignity, independence, and safety are not abstract technical requirements.

That is why GMA has worked deliberately to build security and privacy into every layer we control. That includes engineering, access, information handling, managed devices, and operational resilience, as well as Nora’s governed AI workflow and authorized human response.

We do not believe minimum safeguards are enough when real people place their trust in the system.

We continually ask a simple question: would we accept this level of care and protection for someone in our own family?

Every person deserves safeguards built with that same seriousness.

Explore the Next Step

Let’s understand the person, the environment, and what must remain protected.

Every setting carries different responsibilities. GMA begins by understanding the individual, the environment, and the privacy, access, and continuity requirements that should shape the solution.

No predetermined package. No generic security profile. We begin by listening.

← Back to MyCompass Overview

Gray Matters Alliance
Gray Matters Alliance
119 S. Main St. St. Charles, MO 63301
©2026 by Gray Matters Alliance. All Rights Reserved.