4.9 LINCTV MDM SECURITY AND ARCHITECTURE
|
For IT, networking, and security teams. This is the technical detail behind the summary in article 1.5. The full document is downloadable at the end. |
LincTV MDM runs on Amazon Web Services (AWS) as a cloud-native, multi-tenant service. It's built on defense-in-depth principles: several independent layers of protection, so no single control is the only thing standing between your data and the internet. All infrastructure is defined as code, so every deployment is consistent, auditable, and secure by design.
Your environment is isolated
Each hospital gets its own subdomain on linctv.co and its own dedicated stack of computing resources, inside a virtual private cloud (VPC) that Lincata manages.
- Dedicated network segments: each tenant has its own non-overlapping set of subnets.
- Network ACLs: stateless firewalls at each subnet boundary allow traffic only within a tenant's own resources, blocking cross-tenant traffic at the packet level.
- Security groups: stateful firewalls around every compute and database resource enforce least-privilege access. For example, the database accepts connections only from the application server, never from the internet.
Nothing critical faces the internet
- Private by default: the application (ECS Fargate), database (Aurora PostgreSQL), and cache (Redis) run only in private subnets, with no public IP addresses.
- Secure edge: all incoming traffic passes through AWS CloudFront, which provides DDoS protection and enforces HTTPS/TLS before anything reaches Lincata's servers.
- Web application firewall: AWS WAF at the edge enforces IP whitelisting and filters malicious traffic patterns.
- VPC endpoints: traffic between the application and AWS services (S3, SES, Secrets Manager) travels over private endpoints and never crosses the public internet.
Data is encrypted at every stage
- At rest: AES-256 encryption on all persistent storage, including Aurora databases, ElastiCache Redis, and S3.
- In transit: TLS 1.2 or higher between clients, load balancers, applications, and databases.
- Secrets: database credentials and API keys are never stored in source code. AWS Secrets Manager injects short-lived credentials into application containers at runtime.
Files are protected
- Signed URLs: private media and documents are served through CloudFront signed URLs, so only authenticated users with a valid session can open them, and direct links can't be shared.
- Origin Access Control: storage buckets are fully private. Only CloudFront can reach them, so no one can bypass the CDN's security controls.
Built to stay consistent
- Serverless compute: AWS Fargate runs the application, removing the risk of managing and patching server operating systems.
- Immutable infrastructure: every infrastructure change is made through Terraform, which prevents configuration drift and applies the same security policies from testing to production.
Architecture diagram

Quick answers for security questionnaires
Question |
Answer |
|---|---|
|
Where is LincTV MDM hosted? |
Amazon Web Services (AWS), in a Lincata-managed VPC. |
|
Is our environment shared with other customers? |
Each tenant has dedicated compute resources and subnets, with firewalls blocking cross-tenant traffic. |
|
Are databases reachable from the internet? |
No. Application, database, and cache run in private subnets with no public IPs. |
|
How is data encrypted at rest? |
AES-256 across databases, caches, and file storage. |
|
How is data encrypted in transit? |
TLS 1.2 or higher end to end. |
|
Is there DDoS protection and a WAF? |
Yes. AWS CloudFront for DDoS protection and AWS WAF at the edge. |
|
How are credentials managed? |
AWS Secrets Manager, injected at runtime. Never in source code. |
|
How are infrastructure changes controlled? |
Terraform (infrastructure as code), applied consistently across environments. |