Security &
Compliance
Your customers trust you with their data. We take that responsibility seriously. Enterprise-grade security baseline for everyone — with HIPAA + BAA included for medical practices.
Included on Every Plan
End-to-End Encryption
All data encrypted in transit (TLS 1.3) and at rest (AES-256). Your customer data is always protected.
SOC 2 Aligned
Enterprise-grade security controls modeled on SOC 2 Type II framework. Audited annually.
Audit Logs
Complete tamper-proof audit trail of every action — logins, record access, modifications, exports.
Role-Based Access Control
Granular permissions let you control exactly who can see and do what. Custom roles per team.
Two-Factor Authentication
Protect accounts with 2FA. Required for admin accounts, optional for all users. SSO available on enterprise plans.
Automated Backups
Daily encrypted backups with 30-day retention. Point-in-time recovery available on enterprise plans.
GDPR Compliant
Data processing compliant with GDPR. Data residency options available for EU and international clients.
Incident Response
24/7 security monitoring with defined incident response procedures and breach notification protocols.
Secure Infrastructure
Hosted on enterprise cloud infrastructure with DDoS protection, WAF, and network isolation.
Data Portability
Export all your data at any time. CSV, JSON, and PDF exports for all records.
For MedSpas & Medical Practices
Additional compliance and clinical safeguards are included automatically on MedSpa and dermatology plans.
HIPAA Compliance
Full HIPAA compliance built into every MedSpa and dermatology feature. Technical, administrative, and physical safeguards covered.
BAA Included
Business Associate Agreement signed and included with every MedSpa plan at no extra cost.
PHI Access Audit
Every read of protected health information is logged with user, timestamp, IP, and request path.
Questions About Security?
Our security team is happy to discuss compliance requirements and share our security documentation.