Security & Compliance

Serious about the data you put in our hands.

Enterprise buyers ask for a security page before they ask for a quote. This is it. The posture, the practices, and the commitments — documented, not implied.

Compliance posture

Where we stand, today.

SOC 2 Type IPlanned

A SOC 2 Type I audit is planned, not yet booked or completed. The underlying practices — access logging, change management, incident response — are how we work today.

HIPAADesign intent

AuditGrid is built to HIPAA-aligned practices: PHI encrypted in transit and at rest, append-only audit logging, role-scoped data access. BAAs are executed as healthcare customers onboard.

GDPR / CCPAPractices in place

Data processing terms available on request, current subprocessor list shared on request, and a 30-day target for user data deletion requests.

Penetration testingPlanned

Independent penetration testing is planned as our SaaS products reach production scale. We have not commissioned one yet, and we are not going to imply otherwise.

Vulnerability disclosureOpen

Responsible disclosure accepted at joe@gatorbyte.net. 90-day coordinated disclosure window.

How we build

The six pillars of a defensible build.

Encryption in transit and at rest

TLS in transit, encrypted at rest on managed infrastructure, with key management handled by the platform vendor rather than hand-rolled.

Least-privilege access

Role-based access is enforced in the data layer, not only in app code. Accounts see what their role allows and nothing else.

Vetted infrastructure vendors

Hosting, database, email, and monitoring vendors are chosen for their own compliance posture, and BAAs are put in place with them where PHI is involved.

Append-only audit trail

PHI reads and writes are logged with actor, timestamp, and resource ID. Append-only, retained for regulatory-minimum periods.

Written incident response

An incident response plan and runbooks for the most likely incident categories are written down, with notification steps documented.

Continuous monitoring

Alerting on auth anomalies, rate-limit breaches, and unexpected data egress, with a named engineer responsible for responding.

Documentation

What enterprise procurement usually asks for.

Security questionnaires

Send yours — SIG Lite, CAIQ Lite, or your own. We answer it directly.

Data Processing Addendum (DPA)

We will work from your DPA, or draft one for the engagement.

Subprocessor list

Current vendor list on request, with notice before we add one.

Business Associate Agreement

Executed with the customer and infra vendors as a healthcare engagement onboards.

Incident response plan

Written plan and runbooks for the most likely incident categories.

Architecture and access review

How the system is built, who can reach what, walked through under NDA.

FAQ

Answers to the questions procurement usually asks.

Is GatorByte SOC 2 certified?

No. A SOC 2 Type I audit is planned, and we will say so plainly here the day it is booked and again when it is complete. The practices an audit looks at — access logging, change management, incident response, vendor management — are how we already work, and we can walk through our control notes under NDA.

Do you sign BAAs for healthcare engagements?

Yes. We build healthcare software to HIPAA-aligned practices, and we execute BAAs with the customer and with the infrastructure vendors involved as each healthcare engagement onboards. We will sign your standard BAA or provide ours.

Where does customer data live?

By default: US-East PostgreSQL (Netlify / managed Postgres). Netlify Edge CDN for static assets. We can deploy to customer-controlled infrastructure for regulated enterprise engagements.

How do you handle subprocessors?

We keep a current list of the vendors that touch customer data and share it on request. If we add one, you hear about it before it goes live.

How do we report a vulnerability?

Email joe@gatorbyte.net or use our /.well-known/security.txt file. 90-day coordinated disclosure. We acknowledge within 48 hours and triage within 5 business days.

Responsible disclosure

Found something? Tell us.

We operate a coordinated disclosure program. Report vulnerabilities to joe@gatorbyte.net. We acknowledge within 48 hours, triage within 5 business days, and coordinate disclosure within 90 days.