Your data is protected
at every layer.
QuillsFlow is built for veterinary healthcare โ an environment where clinical data, financial records, and personal information must be protected without compromise. Security is not a feature we added. It is how the platform was architected from day one.
Six layers of
protection.
QuillsFlow is designed with a defence-in-depth approach โ multiple overlapping security controls so that no single point of failure can compromise your data.
๐
Encryption
All data is encrypted at rest and in transit using industry-standard AES-256 encryption. No data is ever stored or transmitted in plain text.
- โAES-256 encryption at rest
- โTLS 1.3 for all data in transit
- โEncrypted database backups
- โSecure key management
๐ค
Access Control
Role-based access controls ensure every team member sees only the data they need. Permissions are set at the user, role, and location level.
- โRole-based permissions (vet, tech, front desk)
- โMulti-factor authentication
- โSession timeout enforcement
- โAdmin audit trail for all access
๐
Audit Logging
Every action taken in QuillsFlow is logged with a timestamp, user ID, and IP address. Logs are tamper-proof and retained for a minimum of 7 years.
- โFull audit trail for all clinical records
- โClaim submission and modification logs
- โLogin and access event logging
- โ7-year minimum retention
โ๏ธ
Infrastructure
QuillsFlow runs on US-based, HIPAA-eligible cloud infrastructure. Data never leaves US jurisdiction. Redundant systems ensure 99.9% uptime.
- โUS-only data residency
- โHIPAA-eligible cloud infrastructure
- โAutomated failover and redundancy
- โDaily encrypted backups
๐
Vulnerability Management
QuillsFlow conducts regular security assessments, penetration testing, and automated vulnerability scanning to identify and remediate risks proactively.
- โAnnual third-party penetration tests
- โAutomated dependency scanning
- โSecurity patch management
- โResponsible disclosure program
๐จ
Incident Response
In the unlikely event of a security incident, QuillsFlow has a documented response plan with defined timelines for notification and remediation.
- โDocumented incident response plan
- โ72-hour breach notification (HIPAA)
- โDedicated security response team
- โPost-incident review process
Meeting the highest standards.
QuillsFlow is built to meet the compliance requirements of veterinary healthcare โ and the insurance industry it connects to.
HIPAA
Full HIPAA compliance including Privacy Rule, Security Rule, and Breach Notification. Business Associate Agreements available for Enterprise plans.
SOC 2 Type II
Third-party audit of our security, availability, and confidentiality controls. Audit in progress.
PCI DSS
Payment card data handled through PCI-compliant Stripe Terminal. QuillsFlow never stores raw card data.
HITRUST CSF
Certification against the HITRUST Common Security Framework is on our compliance roadmap.
State Privacy Laws
Designed to support compliance with California CCPA and applicable state veterinary data privacy regulations.
Common questions.
Security questions? Talk to us.
Our team is happy to walk through our security architecture, share our compliance documentation, or discuss specific requirements for your organisation.
