SOC 2 Type II — in progress
Underway, not yet certified. We will publish the report and observation period when there is one, and we will not claim it before then.
SOC 2 Type II report, pen-test executive summary, sub-processor list, DPA, HIPAA BAA — all in one envelope, delivered within 24h of request.
The page above is the summary. Full architecture at /security.
Underway, not yet certified. We will publish the report and observation period when there is one, and we will not claim it before then.
BAA available on Enterprise plans. PHI handling controls turned on org-wide; audit-log retention extended.
Standard-clause DPA + sub-processor list + Art. 20 export + Art. 17 deletion. EU-region option.
Payment card data routed through PCI-Level-1 gateways (Stripe / Adyen / Braintree / Razorpay). We never touch or store card numbers.
/settings/access/security
surfaces locked / elevated-failures / deletion-pending users.
Everything a security-review team asks for — kept current, delivered within 24h of request.
One email every ~2 weeks. Honest product notes, no marketing pitches.