Security

Every control, with its true status.

This page lists what protects incident records, and marks each control live, rolling out or planned.

Security controls and their status
ControlWhat it doesStatus
Access
One-time-code sign-inReviewers and managers sign in with a code sent to their email. No shared passwords.Live
Role-based accessSix roles, from reporter to read-only auditor. Each sees only what its role needs.Live
Single sign-on (SAML/OIDC)For Network plans. Roles map from your identity provider.Live
Reporter links without accountsEach link covers one site, is rate limited and cannot read other reports.Live
Data
Encryption in transitTLS on every connection to the app and the API.Live
Encryption at restThe hosting provider encrypts the database and file storage.Live
Organization isolationEvery record belongs to one organization. Every query filters by it.Live
Retention controlsRetention periods per site, plus legal hold, on Regulated and Network.Rolling out
Export and deletionFull CSV and PDF export on every plan. Deletion on request.Live
Audit and proof
Append-only audit trailLogs who changed what and when, for every field. The AI-draft mark stays until a person approves.Live
Signed webhooksEvery event carries an HMAC signature. Replayed events are rejected.Live
Read-only auditor accessGive a surveyor or insurer a time-limited, read-only view of a packet.Rolling out
AI safeguards
A person signsLauren drafts. Nothing is final until a named person approves it.Live
BAA-covered AI providerOn Regulated and Network, Lauren's provider signs a BAA and does not train on your data.Live
No patient information on OpenThe free plan blocks patient identifiers and tells the reporter why.Rolling out
Prompt and output loggingAI inputs and outputs go to the audit trail for review.Live
Operations
Backups and a restore drillAutomated backups, plus a documented restore test before launch.Live
Dependency and secret scanningAutomated checks run on every change.Live
Vulnerability disclosureA security.txt file and a monitored security mailbox.Live
Third-party penetration testAn independent test. A summary will be available under NDA.Planned
SOC 2 Type IIWe are scoping the audit. No certification today; we will publish the report when done.Planned

A team summary, not an audit report. The changelog records when statuses change.

Security packet

Get the details your reviewer needs.

Usually sent within one business day.

  • How data flows, including where AI is called.
  • Sub-processor list with purpose and region.
  • BAA overview, and who is responsible for what.
  • Answers to a standard questionnaire, mapped to the HIPAA Security Rule.

We use your details to respond to this request. No spam, and never any patient information in analytics.

Questions

Security, answered.

Something we missed? Ask us, and a person answers.

Do you sign a BAA?

Yes, on Regulated and Network. The BAA covers the app and the AI provider that processes incident text. Read how we approach HIPAA or request the security packet.

Are you SOC 2 certified or HIPAA certified?

No, and we say so plainly. HIPAA has no official certification, so be wary of any vendor that claims one. SOC 2 is planned. Today we can show the control table, the audit trail and the BAA.

Is patient information used to train AI models?

No. On Regulated and Network, the AI provider has a BAA and may not train on your data. On Open, patient data is not allowed in reports.

Where is data stored?

In the United States, on a major cloud provider. The security packet names the provider, region and sub-processors.

How do I report a vulnerability?

Email security@incidentkit.ai. Our security.txt has the contact and our disclosure policy. We acknowledge reports within two business days.

Does this website send patient information to analytics?

No. This website is not built to receive patient data. Form fields are masked in session replay, and analytics run only after consent. See the privacy policy and cookie policy.

Start free

Review the controls, then see the product.

Create your kit in about ten minutes and report the first incident the same day. Free to start, no card.