Trust Center
Welcome to the iECHO Trust Center. We are committed to ensuring the security, privacy and reliability of our platform for the communities that depend on it.
Encrypted in transit and at rest
Aligned with GDPR and the NIST Cybersecurity Framework
No patient data required, by design
Security
A multilayered defense mapped to the NIST Cybersecurity Framework: encryption, access control and continuous monitoring.
Read more →
Privacy
What we collect, why, the rights you keep over your data and the features that protect it on the platform.
Read more →
Accessibility
25 languages, keyboard-friendly navigation and our progress toward full WCAG 2.1 AA conformance.
Read more →
User Support
24/7 help resources, fast email and chat support, training sessions, and the community programs that shape iECHO.
Read more →
iECHO system status
Checking status…
Track real-time platform availability, incident updates and uptime history on our public status page. All planned maintenance is communicated well in advance, with reminders sent before the scheduled window.
Our vision
Empowering communities through trusted human connections
Our vision is to build a trusted, human-centered network of frontline workers who can create measurable, meaningful impact within their local communities. By harnessing the power of technology and collaboration, we aim to amplify the reach and effectiveness of community health, education and development initiatives — driven by trust, simplicity and global purpose.
Responsible AI governance
Turning knowledge into wisdom, with people at the center
In a world of information abundance, we are using AI to transform knowledge into wisdom through contextualized support.
- AI should augment human connection, never replace it. Human expertise and validation remain central to the ECHO Model.
- We are committed to using AI responsibly, transparently and in service of the communities we support.
- AI can help overcome language and access barriers, enabling greater participation and inclusion in resource-limited settings.
Core principles
Inclusive by design
Designed with inclusivity in mind, accommodating users across languages, geographies, literacy levels and connectivity. iECHO supports low-bandwidth modes and is optimized for grassroots usability.
Privacy and data integrity
Robust privacy measures ensure that personal and community-level data is protected, and only used for the purpose of enabling positive impact.
Resolving for diversity
The platform brings together diverse perspectives to improve the adoption of relevant solutions by all.
Designed for reusability and scalability
iECHO is designed as a replicable digital public good. Its architecture allows governments, NGOs and organizations to adapt and scale the ECHO Model across contexts, use cases and regions without reinventing the wheel.
Building a trusted human network
iECHO fosters a secure and reliable network for frontline professionals to share knowledge and solve problems collectively. Network effects and discoverability are built into the platform design, while ensuring trust is central to every connection.
Need compliance documentation?
Request additional technical details, compliance standards and white papers for an in-depth understanding of how we safeguard the data of our partners and users.
support@iecho.orgFrequently asked questions
How is my data secured?
We prioritize the privacy of your personal data by implementing state-of-the-art encryption and security measures. Access is restricted to authorized personnel from Project ECHO.
We will never disclose or share your data with a third party.
In addition, Project ECHO compiles summary data on registration, participation, queries, responses to surveys and polls; this data may be used for a variety of purposes, including: generating reports, maps, communication, surveys, quality assurance, evaluation, research and to guide new initiatives.
Is iECHO compliant with international data privacy and security standards?
Yes, iECHO is compliant with global data protection standards, including GDPR, CCPA, and DPDPA. The platform is also certified under ISO27001 towards information security, and has strict security and data privacy measures to safeguard user data.
Does iECHO offer API access for custom integrations?
Yes. iECHO provides RESTful APIs to integrate with third-party tools. Contact support@iecho.org for more information.
How is identity and access management handled on the platform?
iECHO enforces Role-Based Access Control (RBAC) at the organizational level (Owner, Admin, Member, Subject Matter Expert, Participant). User authentication requires email/phone OTP verification, and Multi-Factor Authentication (MFA) is enforced for administrative roles
Is iECHO HIPAA compliant?
iECHO is non-PHI by design. The ECHO model operates strictly on de-identified patient cases, and iECHO does not function as an Electronic Health Record (EHR) or store sensitive patient data, hence HIPAA is not applicable to iECHO.
Who retains ownership of hub and participant data?
Partners retain complete ownership of their program data. Multi-tenant isolation ensures one organization's data remains inaccessible to others. Individual users retain data rights under GDPR and can request data deletion or retrieval through the Data Protection Officer. Contact our Privacy Team for more information.
Does the iECHO Platform use AI?
Currently, iECHO utilizes AI to suggest banner images and program names. We are working on gradually adding more AI features in a thoughtful and responsible manner over the next year, in a way that augments the ECHO model and human connection, never replacing it. Learn more about our Responsible AI Governance principles