Real practices, not aspirational ones
HTTPS is enforced sitewide. Every request to raydiantwebs.com is served over an encrypted connection; plain HTTP requests are redirected automatically.
Account activity is logged. Logins, failed login attempts, and account changes are recorded with IP address, device, and browser information, retained for 90 days on a rolling basis.
Cookie consent is real, not decorative. Analytics and advertising cookies stay off until you actively accept them, and that choice is wired into Google's own Consent Mode, not just a cookie banner that closes and does nothing.
Contact form submissions are consent-tracked. When you submit our contact form, we record the exact consent text you agreed to, along with a timestamp and IP address — so what you agreed to is provable, not just assumed.
Security & compliance FAQ
No. raydiantwebs.com itself does not collect, store, or transmit PHI. Our contact form and cookie consent handle ordinary business inquiries and site analytics, nothing health-related.
There is no official "HIPAA certified" credential for a company or a website to hold — HIPAA compliance is a property of the specific systems that handle PHI, assessed against how they actually work, not a badge you obtain once. What we can tell you honestly: we build the required technical safeguards — encryption, access control, audit logging — into systems we build for clients who do handle PHI, and we sign Business Associate Agreements before any PHI reaches those systems. See our <a href="/services/hipaa-compliant-development">HIPAA-Compliant Development</a> page for what that actually involves.
If your project involves PHI, we sign a Business Associate Agreement before any of it reaches a system we build or operate — this is standard practice for us, not a special request.
Not as a blanket practice across every project — audit scope is typically agreed per project based on what the system handles and what your own compliance requirements call for. Ask us directly about the specific project you have in mind.
Have a specific compliance requirement?
Tell us what you're building and what data it touches — we'll tell you plainly what's actually required, not what's easiest to sell.