Security Last reviewed 6 May 2026

You are legally holding these records. So are we.

Clinical notes are among the most sensitive records a person generates. This page describes what we actually do, in enough detail to be checkable.

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest, with keys managed in a hardware security module and rotated on a fixed schedule. Backups are encrypted with separate keys.

Access on a need-to-know basis

Role-based permissions, enforced per record rather than per screen. Supervisors see what supervision requires; reception sees scheduling and billing, never clinical content.

An audit log you can read

Every view, edit, export and login is written to an append-only log with actor, timestamp and record. It is exportable, and nobody at Verdant can amend it.

Availability you can check

99.95% uptime target, measured externally and published. Point-in-time recovery to any moment in the last 35 days, tested by restore every quarter.

Commitments

What we are on the hook for.

HIPAA

Verdant operates as a Business Associate. We counter-sign a BAA for every US practice at no additional cost and without a minimum plan — you do not have to reach an enterprise tier to be compliant. Workforce training is annual and access reviews are quarterly.

GDPR

Practices in the EU and UK are controllers; Verdant is the processor. A DPA with the standard contractual clauses is included in the terms, and EU data residency is available on the Group plan. Data subject requests — access, rectification, erasure, portability — can be fulfilled from the client record without contacting us.

Data ownership

Your records are yours. Export any client, any date range, or the entire practice in open formats (CSV, JSON, PDF) at any time, on any plan, with no export fee. If you close the account we retain data for 90 days so you can change your mind, then delete it irrecoverably.

Breach notification

If we ever have a confirmed breach affecting your records, we notify you within 24 hours of confirmation — not within the statutory maximum. The notification names the records affected, not just the fact of an incident.

Engineering practice

How the code gets to production.

Most breaches are not exotic. They are an unreviewed change, a stale dependency or a backup nobody ever tried to restore.

Standing controls All active
  • Penetration test by an independent firm, annually, summary available on request
  • Static analysis and dependency scanning on every commit
  • Two-person review on any change touching clinical records or authentication
  • Production access requires hardware key and is logged to the same audit trail
  • Quarterly restore drills against real backups, not simulated ones
  • No client data in staging, ever — seeded fixtures only
Subprocessors

Everyone who touches your data.

The complete list. We give 30 days' notice before adding to it, and you can object.

Verdant subprocessors, their purpose and processing region
Subprocessor Purpose Region
Amazon Web Services Primary hosting and storage eu-north-1 · us-east-1
Stripe Card processing US · IE
Twilio SMS reminders US · IE
Postmark Transactional email US
Cloudflare CDN and DDoS protection Global edge
Responsible disclosure

Found something? We would rather hear it from you.

Report vulnerabilities to security@verdant.example.com. We acknowledge within one business day and aim to have a fix or a timeline within five. We do not pursue legal action against researchers acting in good faith, and we credit anyone who wants credit.

Email the security team
Questions

Send us your security questionnaire.

We answer them in full, without an enterprise plan and without an NDA for the standard sections.

Get in touch

No NDA for the standard sections · Acknowledged within one business day