Security & Compliance

Last Updated: August 16, 2026  |  Security Review: Quarterly (Next: November 2026)

EverFlow Veterinary Codes™ is committed to maintaining the highest standards of security and compliance to protect our users' data and maintain trust in our platform. This document outlines our security measures, compliance standards, and ongoing commitments.

🔒 Security Built With Compliance In Mind
State Veterinary Privacy Law Compliant • Encryption In Transit and At Rest • Pursuing SOC 2 Type II and ISO 27001 Certification as We Scale

1. Security Framework

1.1 Information Security Management

Our security program is built following industry-standard frameworks and best practices, including principles from ISO 27001, the NIST Cybersecurity Framework, and OWASP Top 10.

We have not yet engaged a third-party auditor for formal SOC 2 or ISO 27001 certification. As a pre-revenue platform, we've prioritized building our security architecture around these frameworks now, with formal certification planned once we're onboarding paying customers at a scale that warrants the audit investment. We're happy to walk prospective partners through our current security practices directly.

1.2 Security Organization

2. Technical Security Controls

2.1 Data Encryption

2.2 Access Controls

2.3 Network Security

2.4 Application Security

3. Infrastructure Security

3.1 Cloud Security

Our infrastructure is hosted on enterprise-grade cloud platforms with:

3.2 Backup and Disaster Recovery

4. Compliance Standards

StandardDescriptionStatus
SOC 2 Type IIAnnual audits covering security, availability, processing integrity, confidentiality, and privacy.Pre-audit – planned as we onboard customers
ISO 27001:2013International standard for information security management systems.Pre-audit – planned as we onboard customers
State Veterinary Privacy LawsCompliance with 35 state-level veterinary confidentiality statutes.Compliant
GDPREuropean General Data Protection Regulation for international users.Designed with GDPR principles in mind
CCPA/CPRACalifornia Consumer Privacy Act and amendments for California residents.Designed with CCPA/CPRA principles in mind
FedRAMPFederal Risk and Authorization Management Program for government use.Not currently applicable

5. Veterinary-Specific Compliance

5.1 State Veterinary Privacy Laws

We comply with veterinary confidentiality requirements across all 35 states with specific statutes:

RequirementOur ImplementationMonitoring
Client consent for data sharingExplicit consent workflowsAudit logs for all consents
5-day response to authorized requestsAutomated request processingSLA monitoring and alerts
Secure record storageEncrypted databases and backupsRegular security assessments
Professional confidentialityRole-based access controlsAccess logging and reviews

5.2 Academic Partnership Compliance

Our partnership with Virginia Tech VTSL requires adherence to academic research standards:

6. Data Protection and Privacy

6.1 Data Classification

6.2 Data Minimization

6.3 Data Subject Rights

7. Incident Response and Business Continuity

7.1 Security Incident Response

  1. Detection: 24/7 monitoring and alerting systems
  2. Analysis: Rapid triage and impact assessment
  3. Containment: Immediate threat isolation and mitigation
  4. Eradication: Root cause analysis and remediation
  5. Recovery: Service restoration and validation
  6. Lessons Learned: Post-incident review and improvements

7.2 Breach Notification

In the event of a data breach, we commit to:

7.3 Business Continuity

8. Third-Party Security

8.1 Vendor Risk Management

All third-party vendors undergo rigorous security assessment:

8.2 Approved Vendors

We maintain a list of pre-approved vendors that meet our security standards for common services like cloud infrastructure, monitoring, and support tools.

9. Security Training and Awareness

9.1 Employee Training

9.2 Customer Security Resources

10. Audit and Monitoring

10.1 Continuous Monitoring

10.2 Regular Assessments

11. Certifications and Attestations

Certification Status

We have not yet engaged third-party auditors for SOC 2 Type II or ISO 27001 certification. As a pre-revenue platform, we've prioritized building our security architecture around these frameworks now, with formal certification planned once we're onboarding paying customers at a scale that warrants the audit investment.

Questions About Our Security Practices

We're happy to walk prospective partners through our current security practices directly, and to complete security questionnaires as part of your vendor evaluation process. Contact our security team for details.

12. Security Contact and Reporting

12.1 Vulnerability Reporting

We encourage responsible disclosure of security vulnerabilities. Please report security issues to:

12.2 Security Advisory

Subscribe to our security advisory mailing list for updates on:

Security Team Contact

EverFlow Veterinary Codes™, LLC
Chief Information Security Officer
Email: security@everflowvet.com
Phone: +1 602-531-1256 (ext. 3)
Secure Portal: security.everflowvet.com
Status Page: status.everflowvet.com

Emergency Security Hotline: +1 602-531-SECURITY (24/7)