Security & Compliance

Last Updated: October 26, 2025
Security Review: Quarterly (Next: January 2026)

EverFlow Veterinary Codes is committed to maintaining the highest standards of security and compliance to protect our users' data and maintain trust in our platform. This document outlines our security measures, compliance standards, and ongoing commitments.

🔒 Enterprise-Grade Security

SOC 2 Type II Compliant • ISO 27001 Certified • State Veterinary Privacy Law Compliant

1. Security Framework

1.1 Information Security Management

Our security program is built on industry-standard frameworks and best practices:

1.2 Security Organization

Our security governance structure includes:

2. Technical Security Controls

2.1 Data Encryption

2.2 Access Controls

2.3 Network Security

2.4 Application Security

3. Infrastructure Security

3.1 Cloud Security

Our infrastructure is hosted on enterprise-grade cloud platforms with:

3.2 Backup and Disaster Recovery

4. Compliance Standards

SOC 2 Type II

Annual audits covering security, availability, processing integrity, confidentiality, and privacy.

Compliant

ISO 27001:2013

International standard for information security management systems.

Certified

State Veterinary Privacy Laws

Compliance with 35 state-level veterinary confidentiality statutes.

Compliant

GDPR

European General Data Protection Regulation for international users.

Compliant

CCPA/CPRA

California Consumer Privacy Act and amendments for California residents.

Compliant

FedRAMP

Federal Risk and Authorization Management Program for government use.

Planned 2026

5. Veterinary-Specific Compliance

5.1 State Veterinary Privacy Laws

We comply with veterinary confidentiality requirements across all 35 states with specific statutes:

Requirement Our Implementation Monitoring
Client consent for data sharing Explicit consent workflows Audit logs for all consents
5-day response to authorized requests Automated request processing SLA monitoring and alerts
Secure record storage Encrypted databases and backups Regular security assessments
Professional confidentiality Role-based access controls Access logging and reviews

5.2 Academic Partnership Compliance

Our partnership with Virginia Tech VTSL requires adherence to academic research standards:

6. Data Protection and Privacy

6.1 Data Classification

We classify data based on sensitivity and apply appropriate controls:

6.2 Data Minimization

6.3 Data Subject Rights

We provide comprehensive data subject rights management:

7. Incident Response and Business Continuity

7.1 Security Incident Response

Our incident response process includes:

  1. Detection: 24/7 monitoring and alerting systems
  2. Analysis: Rapid triage and impact assessment
  3. Containment: Immediate threat isolation and mitigation
  4. Eradication: Root cause analysis and remediation
  5. Recovery: Service restoration and validation
  6. Lessons Learned: Post-incident review and improvements

7.2 Breach Notification

In the event of a data breach, we commit to:

7.3 Business Continuity

8. Third-Party Security

8.1 Vendor Risk Management

All third-party vendors undergo rigorous security assessment:

8.2 Approved Vendors

We maintain a list of pre-approved vendors that meet our security standards for common services like cloud infrastructure, monitoring, and support tools.

9. Security Training and Awareness

9.1 Employee Training

9.2 Customer Security Resources

10. Audit and Monitoring

10.1 Continuous Monitoring

10.2 Regular Assessments

11. Certifications and Attestations

Current Certifications

  • SOC 2 Type II: Valid through December 2025
  • ISO 27001:2013: Valid through September 2026
  • Cloud Security Alliance (CSA): STAR Level 2

Audit Reports Available

Current SOC 2 Type II reports are available to customers under NDA. Contact our security team for access.

12. Security Contact and Reporting

12.1 Vulnerability Reporting

We encourage responsible disclosure of security vulnerabilities. Please report security issues to:

12.2 Security Advisory

Subscribe to our security advisory mailing list for updates on:

Security Team Contact

EverFlow Veterinary Codes, LLC

Chief Information Security Officer

Email: security@everflowvet.com

Phone: +1 321-559-1671 (ext. 3)

Secure Portal: https://security.everflowvet.com

Status Page: https://status.everflowvet.com

Emergency Security Hotline: +1 602-531-SECURITY (24/7)