ELH Health is the multi-site, BAA-ready, SSO-by-default platform we built for organizations who need to deliver coaching, nutrition, and biometric monitoring at scale — without ever explaining their data flow to a board for the third time.
Most health platforms ask the customer to bolt on the controls. We start with them, then add the polish.
Org → site → trainer → member. A 200-location chain runs as a single tenant; a regional manager only sees their region; a trainer only sees their roster.
SAML 2.0 (Okta, Azure AD, OneLogin, Google) and OIDC. Make password login optional, or disable it entirely per-org.
Every read of member health data is logged with a SHA-256 chain digest. Tamper-evident. Exportable. Reviewed quarterly with you.
Inbound user provisioning from your IdP. New employees show up automatically; departures are deactivated within minutes.
The same nutrition, cycle, and glucose intelligence powering FitApp — wrapped, versioned, and audited.
ELH Health is sold via direct contract — not self-service checkout. We license per Monthly Active User with a banded floor + overage rate. Every customer gets a deployment partner, security review, and quarterly business review baked into the price.
For tier-1 chains, telehealth operators, and clinical programs that require: single-tenant database (private region), customer-managed encryption keys (CMK), data residency (US-East / US-West / EU / Canada), per-tenant API gateway, named security engineer, 1-hour incident response 24×7, on-site security review, bridge letters. Multi-year terms, custom SLAs.
Active = unique authenticated session in a 30-day window. Stricter engagement-based MAU available with a per-MAU rate adjustment. Multi-year commit discounts available.
We share architecture diagrams, data-flow documents, our SBOM, and a draft DPA on request — before any data flows.
BAA available. PHI encrypted at rest and in transit, accessed via tamper-evident audit chain.
Type II audit in progress with a top-three CPA firm. Bridge letter available.
Per-region data residency, right-to-erasure tooling, automated DSAR fulfillment.
US-East default. EU and Canadian regions on Enterprise Plus.
AES-256 at rest, TLS 1.2+ in transit, customer-managed keys (CMK) on Plus.
Annual external pentest by a specialist firm. Findings shared on request.
Every Enterprise contract includes 4–8 weeks of guided implementation: SSO setup, SCIM mapping, brand configuration, trainer training, member rollout, security review.