All controls monitoredLast updated October 2026Hosted in the United StatesAppend-only audit on every action
Legal by Rose
Compliance

Frameworks & certifications

The standards we build and audit against. Reports and attestations are available under NDA in Documents.

In progressSOC 2 Type IIControls operating from day one; Type II observation window underway, with SOC 1 to follow.
BAAs availableHIPAAPHI handling for medical-records and injury files; Business Associate Agreement on request.
In progressISO 27001Information-security management system being formalized toward certification.
AlignedGDPR & CCPA / CPRAData exportability, deletion and privacy-rights handling built into the platform.

Questions from your security team?

We share our SOC 2 report, subprocessor registry, BAA and DPA under NDA, and will walk your team through the controls.

Start a security review