Security & compliance

The short version: this is your staff’s compliance record, not your patients’ charts.

This page is written for whoever runs your vendor review. It states what we have and what we don't, because you should be able to make this decision without taking our word for anything.

Where we stand on certifications

Being direct, because these are the two questions every health system asks first:

Not audited

SOC 2

We do not have a SOC 2 report. Not a Type I and not a Type II. A SOC 2 is an attestation issued by a licensed CPA firm after an observation window — it isn't something a vendor can switch on per customer or per location, and we're not going to describe it that way. It is on our roadmap, and we'll say so plainly until the day a real report exists.

Out of scope

HIPAA

We are not a HIPAA Business Associate, and we have no BAA in place — because this product doesn't process protected health information at all. It exists to help your clinic document its ownOSHA and HIPAA compliance program — fridge temperatures, crash cart checks, staff credentials, training records — not to hold a patient chart, an appointment, or anything with a patient's name on it. There is no patient table in this product's schema.

The condition that would change this: if we ever add a feature that carries a patient identifier — a name attached to anything — we become a Business Associate at that moment. A signed BAA and real HIPAA controls become prerequisites for shipping it, not follow-up work. We'd rather you hold us to that in writing now than discover it later.

What we actually store

Employment and compliance records for your staff — never anything about your patients.

SurfaceWhat's storedRetention
Staff accountsName, legal name, work email, job title, role, and an optional profile photo they upload themselves. No home address, no SSN, no date of birth.Kept while the account is active
Compliance logsEquipment readings and checklist answers (a fridge temperature, an O2 cylinder's pressure, a narcotics count), who filed it and when, where it was filed from, and an optional photo of the equipment — never a patient.Kept indefinitelyThis is the compliance record itself — the whole point is that it still exists when a surveyor asks for it. Rows are never edited or deleted; a correction adds a new, linked entry and keeps the original.
CredentialsLicense/certification type, issuing body, and expiry date, plus an optional photo of the physical card.Kept while the credential is on file
ObligationsA deadline register — title, due date, who owns it, the regulation or contract behind it, and the evidence note a person writes themselves when they complete it.Kept indefinitely
Inventory (add-on)A stock catalog and count history — quantity, expiration, an optional photo of the shelf or item.Kept indefinitely
Audit logEvery administrative action — who signed in, who changed a setting, who moved a due date — with the actor and timestamp.Kept indefinitely

Controls in place today

  • No patient data, by design. There is no patient table anywhere in this product's schema — not a missing feature, an absent one.
  • No self-signup. Every account is invited by an administrator. Signing in is by Google, or an emailed six-digit code that expires in ten minutes and is capped at five wrong attempts before it's dead — the code, not the account.
  • Mandatory second factor for anyone with authority over other people's records. Administrators, owners, and clinical leads must enroll a TOTP authenticator to reach anything. There is no setting in the app to turn this off.
  • Row-level security on every table, enforced by the database. Each row is scoped to one clinic; a bug in a route can ask for the wrong org's data and simply not receive it, because the database — not application code — is what refuses it.
  • The compliance ledger is append-only, and the database enforces it. Editing or deleting a filed log is refused by a trigger, not just discouraged by the interface. A correction inserts a new row pointing at the one it replaces and requires a written reason; nothing is ever silently changed.
  • Each log entry is chained to the one before it with a hash. The same idea a tamper-evident ledger uses elsewhere — a row edited outside the application would break the chain visibly.
  • Photos live in a private bucket, reachable only through a short-lived signed link generated on request, never a public URL.
  • One narrow, disclosed use of a third-party AI model: reading a tightly cropped photo of a digital display back as a proposed number — nothing else is sent, the image is used for that one call and never saved, and the record itself is written the same way a typed number would be.
  • Bearer links (the inspector view, calendar subscriptions) are 256-bit random tokens. Only a hash is ever stored, so a database copy yields no working link, and every link is individually revocable.
  • A lapsed subscription makes an account read-only, never deletes anything. A clinic's own compliance history is never held hostage to a billing problem.
  • Session cookies are signed and carry a revocation epoch. Deactivating someone ends every session they hold, everywhere, on their next request.
  • Privileged keys never reach the browser. The database service-role key and every third-party API key live only in server-side environment variables.
  • TLS everywhere, terminated at the edge, with no plaintext origin.

Subprocessors

These vendors process data on our behalf. Several hold their own SOC 2 — that is their attestation covering their infrastructure, and we list it as context, not as a substitute for one of ours.

VendorPurposeSees
VercelHosting, CDN, edge routingRequests in transit
SupabasePostgres database and file storageEverything in the table above
GoogleSign-inEmail address, for identity only
ResendTransactional email — alerts, digests, sign-in codesRecipient address and message content
StripeBillingPayment details, never our servers
AnthropicThe one narrow vision-read call described aboveA cropped equipment-display photo, not retained by us

Questions we haven't answered here

If your security team has a questionnaire, send it — we'll fill it in honestly, including the rows where the answer is “not yet.”

Send it to us