Skip to main content
Data Security

Your data is protected
at every layer.

QuillsFlow is built for veterinary healthcare โ€” an environment where clinical data, financial records, and personal information must be protected without compromise. Security is not a feature we added. It is how the platform was architected from day one.

๐Ÿ”’ HIPAA Compliant๐Ÿ›ก SOC 2 Type II (In Progress)๐Ÿ† HITRUST CSF (Planned)๐Ÿ” AES-256 Encryptionโ˜๏ธ US-Based Infrastructureโœ“ Role-Based Access Control๐Ÿ“‹ Full Audit Logging
Security pillars

Six layers of
protection.

QuillsFlow is designed with a defence-in-depth approach โ€” multiple overlapping security controls so that no single point of failure can compromise your data.

๐Ÿ”

Encryption

All data is encrypted at rest and in transit using industry-standard AES-256 encryption. No data is ever stored or transmitted in plain text.

  • โœ“AES-256 encryption at rest
  • โœ“TLS 1.3 for all data in transit
  • โœ“Encrypted database backups
  • โœ“Secure key management

๐Ÿ‘ค

Access Control

Role-based access controls ensure every team member sees only the data they need. Permissions are set at the user, role, and location level.

  • โœ“Role-based permissions (vet, tech, front desk)
  • โœ“Multi-factor authentication
  • โœ“Session timeout enforcement
  • โœ“Admin audit trail for all access

๐Ÿ“‹

Audit Logging

Every action taken in QuillsFlow is logged with a timestamp, user ID, and IP address. Logs are tamper-proof and retained for a minimum of 7 years.

  • โœ“Full audit trail for all clinical records
  • โœ“Claim submission and modification logs
  • โœ“Login and access event logging
  • โœ“7-year minimum retention

โ˜๏ธ

Infrastructure

QuillsFlow runs on US-based, HIPAA-eligible cloud infrastructure. Data never leaves US jurisdiction. Redundant systems ensure 99.9% uptime.

  • โœ“US-only data residency
  • โœ“HIPAA-eligible cloud infrastructure
  • โœ“Automated failover and redundancy
  • โœ“Daily encrypted backups

๐Ÿ”

Vulnerability Management

QuillsFlow conducts regular security assessments, penetration testing, and automated vulnerability scanning to identify and remediate risks proactively.

  • โœ“Annual third-party penetration tests
  • โœ“Automated dependency scanning
  • โœ“Security patch management
  • โœ“Responsible disclosure program

๐Ÿšจ

Incident Response

In the unlikely event of a security incident, QuillsFlow has a documented response plan with defined timelines for notification and remediation.

  • โœ“Documented incident response plan
  • โœ“72-hour breach notification (HIPAA)
  • โœ“Dedicated security response team
  • โœ“Post-incident review process
Compliance

Meeting the highest standards.

QuillsFlow is built to meet the compliance requirements of veterinary healthcare โ€” and the insurance industry it connects to.

๐Ÿฅ

HIPAA

Full HIPAA compliance including Privacy Rule, Security Rule, and Breach Notification. Business Associate Agreements available for Enterprise plans.

Compliant
๐Ÿ”

SOC 2 Type II

Third-party audit of our security, availability, and confidentiality controls. Audit in progress.

In Progress
๐Ÿ’ณ

PCI DSS

Payment card data handled through PCI-compliant Stripe Terminal. QuillsFlow never stores raw card data.

Compliant via Stripe
๐Ÿ†

HITRUST CSF

Certification against the HITRUST Common Security Framework is on our compliance roadmap.

Planned
๐ŸŒ

State Privacy Laws

Designed to support compliance with California CCPA and applicable state veterinary data privacy regulations.

Supported
Security FAQ

Common questions.

Security questions? Talk to us.

Our team is happy to walk through our security architecture, share our compliance documentation, or discuss specific requirements for your organisation.