Security
Where your records live, who can see them and where our SOC 2 audit stands.
The controls
What a reviewer can check
Where your data lives
- United States hosting
- AWS us-east-1, with application services in private subnets and no public database.
- Encrypted at rest
- The database is encrypted under a rotating AWS KMS key we manage. Secrets and files sit in encrypted storage, and backups are kept for 30 days.
- Encrypted in transit
- HTTPS on TLS 1.3 and 1.2, and TLS-only connections to the database.
- Monitored
- CloudTrail, GuardDuty, a web application firewall and alarms to on-call.
Who sees what
- Separate organizations
- Shared infrastructure, with database controls keeping each organization’s records apart.
- Roles by feature and project
- Use the built-in roles or build your own, then grant them for one project or the whole organization, with an optional expiry date.
- Sessions you control
- Revoke one session or all of them.
- Single sign-on
- Coming soon. Today login is email and password.
Your data and AI
- Yours to take
- Export observations with their photos, and keep every report as a PDF.
- AI output is labeled
- AI suggestions on a record are labeled as AI, and your team can change any of them. When someone changes the AI risk analysis, the original is kept.
- Dictation is not kept
- When you dictate into a field, the audio is deleted once it is transcribed.
Compliance
- SOC 2 audit in progress
- We are working with Vanta toward our SOC 2 report. Ask us for our security documentation.
- A history of changes
- Changes to compliance schedules, site groups and chemical records keep an audit history.
Bring your security review to the demo
Send us your questionnaire and we answer it ourselves before your first project.