SOC 2 Aligned·HIPAA·GDPR

Security &
Compliance

Your customers trust you with their data. We take that responsibility seriously. Enterprise-grade security baseline for everyone — with HIPAA + BAA included for medical practices.

Baseline Security

Included on Every Plan

End-to-End Encryption

All data encrypted in transit (TLS 1.3) and at rest (AES-256). Your customer data is always protected.

SOC 2 Aligned

Enterprise-grade security controls modeled on SOC 2 Type II framework. Audited annually.

Audit Logs

Complete tamper-proof audit trail of every action — logins, record access, modifications, exports.

Role-Based Access Control

Granular permissions let you control exactly who can see and do what. Custom roles per team.

Two-Factor Authentication

Protect accounts with 2FA. Required for admin accounts, optional for all users. SSO available on enterprise plans.

Automated Backups

Daily encrypted backups with 30-day retention. Point-in-time recovery available on enterprise plans.

GDPR Compliant

Data processing compliant with GDPR. Data residency options available for EU and international clients.

Incident Response

24/7 security monitoring with defined incident response procedures and breach notification protocols.

Secure Infrastructure

Hosted on enterprise cloud infrastructure with DDoS protection, WAF, and network isolation.

Data Portability

Export all your data at any time. CSV, JSON, and PDF exports for all records.

Healthcare Add-Ons

For MedSpas & Medical Practices

Additional compliance and clinical safeguards are included automatically on MedSpa and dermatology plans.

HIPAA Compliance

Full HIPAA compliance built into every MedSpa and dermatology feature. Technical, administrative, and physical safeguards covered.

BAA Included

Business Associate Agreement signed and included with every MedSpa plan at no extra cost.

PHI Access Audit

Every read of protected health information is logged with user, timestamp, IP, and request path.

Questions About Security?

Our security team is happy to discuss compliance requirements and share our security documentation.