This whitepaper outlines Sema4's approach to cybersecurity and data protection, focusing on the management of sensitive data during business-critical process automation. It details the company's commitment to maintaining confidentiality and secure operations through various initiatives, including compliance with SOC 2 Type II and HIPAA standards. The document describes the importance of fostering a security-minded culture within the organization, emphasizing employee training and operational security measures. It also discusses the implementation of third-party penetration testing and the principles guiding product security, such as the principle of least privilege and tenant separation. Additionally, the whitepaper explains the architecture of the Sema4 Control Room, which operates on AWS infrastructure, ensuring data encryption in transit and at rest. The document further highlights the features of the Control Room Vault for managing sensitive credentials securely, as well as the enterprise offerings tailored for clients with strict regulatory requirements.