Security & compliance
Audit-ready by design
Security & compliance
Built for regulated industries
Compliance-first, not compliance-bolted-on.
SOC 2 Type II
Independently audited security controls covering availability, confidentiality, and processing integrity.
HIPAA-Ready
Built with HIPAA technical safeguards in mind. Business Associate Agreements (BAA) available on all plans.
GDPR Compliant
Data residency options, right-to-erasure support, and DPA agreements for organizations operating in the EU.
Immutable Audit Trail
Every action — profile update, approval decision, document upload — is logged with actor, timestamp, and a before/after snapshot.
Enterprise Infrastructure
Hosted on SOC 2-certified cloud infrastructure with encryption at rest (AES-256) and in transit (TLS 1.3).
99.9% Uptime SLA
Enterprise plans include an uptime SLA with automatic failover, daily backups, and disaster recovery.
The details
What sits behind the badges.
Encryption everywhere
Data is encrypted at rest with AES-256 and in transit with TLS 1.3. Encryption keys are managed and rotated by our infrastructure provider.
Access control & RBAC
Role-based access control governs who can see and do what. SSO and SCIM provisioning are available so access follows your identity provider.
Immutable audit logging
Every profile change, approval decision, and document action is recorded with actor, timestamp, and a before/after snapshot — and cannot be edited after the fact.
Enterprise infrastructure
Hosted on SOC 2-certified cloud infrastructure with automated daily backups, failover, and disaster recovery.
Data residency
Data residency options are available for organizations operating under EU and other regional requirements.
Subprocessors & BAAs
We maintain a current subprocessor list and offer Business Associate Agreements on all plans for HIPAA-covered workflows.
Need our SOC 2 report, subprocessor list, or a completed security questionnaire? Contact us and we’ll share what your review requires.