Encryption everywhere
TLS 1.3 in transit, AES-256 at rest, with keys managed in a hardware security module and rotated on a fixed schedule. Backups are encrypted with separate keys.
Clinical notes are among the most sensitive records a person generates. This page describes what we actually do, in enough detail to be checkable.
TLS 1.3 in transit, AES-256 at rest, with keys managed in a hardware security module and rotated on a fixed schedule. Backups are encrypted with separate keys.
Role-based permissions, enforced per record rather than per screen. Supervisors see what supervision requires; reception sees scheduling and billing, never clinical content.
Every view, edit, export and login is written to an append-only log with actor, timestamp and record. It is exportable, and nobody at Verdant can amend it.
99.95% uptime target, measured externally and published. Point-in-time recovery to any moment in the last 35 days, tested by restore every quarter.
Verdant operates as a Business Associate. We counter-sign a BAA for every US practice at no additional cost and without a minimum plan — you do not have to reach an enterprise tier to be compliant. Workforce training is annual and access reviews are quarterly.
Practices in the EU and UK are controllers; Verdant is the processor. A DPA with the standard contractual clauses is included in the terms, and EU data residency is available on the Group plan. Data subject requests — access, rectification, erasure, portability — can be fulfilled from the client record without contacting us.
Your records are yours. Export any client, any date range, or the entire practice in open formats (CSV, JSON, PDF) at any time, on any plan, with no export fee. If you close the account we retain data for 90 days so you can change your mind, then delete it irrecoverably.
If we ever have a confirmed breach affecting your records, we notify you within 24 hours of confirmation — not within the statutory maximum. The notification names the records affected, not just the fact of an incident.
Most breaches are not exotic. They are an unreviewed change, a stale dependency or a backup nobody ever tried to restore.
The complete list. We give 30 days' notice before adding to it, and you can object.
| Subprocessor | Purpose | Region |
|---|---|---|
| Amazon Web Services | Primary hosting and storage | eu-north-1 · us-east-1 |
| Stripe | Card processing | US · IE |
| Twilio | SMS reminders | US · IE |
| Postmark | Transactional email | US |
| Cloudflare | CDN and DDoS protection | Global edge |
Report vulnerabilities to security@verdant.example.com. We acknowledge within one business day and aim to have a fix or a timeline within five. We do not pursue legal action against researchers acting in good faith, and we credit anyone who wants credit.
Email the security teamWe answer them in full, without an enterprise plan and without an NDA for the standard sections.
Get in touchNo NDA for the standard sections · Acknowledged within one business day