Security & Compliance
Serious about the data you put in our hands.
Enterprise buyers ask for a security page before they ask for a quote. This is it. The posture, the practices, and the commitments — documented, not implied.
Compliance posture
Where we stand, today.
A SOC 2 Type I audit is planned, not yet booked or completed. The underlying practices — access logging, change management, incident response — are how we work today.
AuditGrid is built to HIPAA-aligned practices: PHI encrypted in transit and at rest, append-only audit logging, role-scoped data access. BAAs are executed as healthcare customers onboard.
Data processing terms available on request, current subprocessor list shared on request, and a 30-day target for user data deletion requests.
Independent penetration testing is planned as our SaaS products reach production scale. We have not commissioned one yet, and we are not going to imply otherwise.
Responsible disclosure accepted at joe@gatorbyte.net. 90-day coordinated disclosure window.
How we build
The six pillars of a defensible build.
Encryption in transit and at rest
TLS in transit, encrypted at rest on managed infrastructure, with key management handled by the platform vendor rather than hand-rolled.
Least-privilege access
Role-based access is enforced in the data layer, not only in app code. Accounts see what their role allows and nothing else.
Vetted infrastructure vendors
Hosting, database, email, and monitoring vendors are chosen for their own compliance posture, and BAAs are put in place with them where PHI is involved.
Append-only audit trail
PHI reads and writes are logged with actor, timestamp, and resource ID. Append-only, retained for regulatory-minimum periods.
Written incident response
An incident response plan and runbooks for the most likely incident categories are written down, with notification steps documented.
Continuous monitoring
Alerting on auth anomalies, rate-limit breaches, and unexpected data egress, with a named engineer responsible for responding.
Documentation
What enterprise procurement usually asks for.
Security questionnaires
Send yours — SIG Lite, CAIQ Lite, or your own. We answer it directly.
Data Processing Addendum (DPA)
We will work from your DPA, or draft one for the engagement.
Subprocessor list
Current vendor list on request, with notice before we add one.
Business Associate Agreement
Executed with the customer and infra vendors as a healthcare engagement onboards.
Incident response plan
Written plan and runbooks for the most likely incident categories.
Architecture and access review
How the system is built, who can reach what, walked through under NDA.
FAQ
Answers to the questions procurement usually asks.
Is GatorByte SOC 2 certified?
No. A SOC 2 Type I audit is planned, and we will say so plainly here the day it is booked and again when it is complete. The practices an audit looks at — access logging, change management, incident response, vendor management — are how we already work, and we can walk through our control notes under NDA.
Do you sign BAAs for healthcare engagements?
Yes. We build healthcare software to HIPAA-aligned practices, and we execute BAAs with the customer and with the infrastructure vendors involved as each healthcare engagement onboards. We will sign your standard BAA or provide ours.
Where does customer data live?
By default: US-East PostgreSQL (Netlify / managed Postgres). Netlify Edge CDN for static assets. We can deploy to customer-controlled infrastructure for regulated enterprise engagements.
How do you handle subprocessors?
We keep a current list of the vendors that touch customer data and share it on request. If we add one, you hear about it before it goes live.
How do we report a vulnerability?
Email joe@gatorbyte.net or use our /.well-known/security.txt file. 90-day coordinated disclosure. We acknowledge within 48 hours and triage within 5 business days.
Responsible disclosure
Found something? Tell us.
We operate a coordinated disclosure program. Report vulnerabilities to joe@gatorbyte.net. We acknowledge within 48 hours, triage within 5 business days, and coordinate disclosure within 90 days.
