Skip to main content
Trust Center

Security, data handling and AI governance.

Veterinary clinical, financial and personal data deserves layered protection. This Trust Center explains the controls behind QuillsFlow, mapped to the AICPA SOC 2 Trust Services Criteria. Each control is labeled as current design, pilot, or planned.

SOC 2 criteria mapped · audit planned Encryption in transit & at rest US data region Clinician-signed AI output
Standard

Mapped to the SOC 2 Trust Services Criteria.

SOC 2 is the AICPA framework for how service providers protect customer data. We use its criteria as the standard for the Quill application and supporting systems. An independent SOC 2 audit is planned; no report has been issued yet.

Tap or click a criterion to pin its details; tap it again or use Reset to return to the overview. Arrow keys move between criteria, Esc resets.

Showing CC1: Control environment. Who is accountable for security and how expectations are set.

CC1 · Control environment

Current design

Who is accountable for security and how expectations are set.

  • Named security owner and leadership review
  • Acceptable-use and confidentiality agreements for staff
  • Security responsibilities written into role descriptions

Quill implementation detail

  • Security owner reviews access, incidents and vendor changes on a set cadence
  • All staff and contractor accounts sign confidentiality terms before platform access is provisioned
  • Engineering, support and clinical-review responsibilities are separated so no single role can change data unreviewed

Quill's commitment: veterinary clinical, financial and personal data is protected by layered technical controls — encryption in transit and at rest, per-clinic data isolation, logged access and reviewed changes. Controls are mapped to the AICPA SOC 2 Trust Services Criteria; an independent audit is planned and no report has been issued yet.

Security controls

Eight control families.

Each family starts with what it means for your clinic, followed by the specific controls.

Current design

Identity & access

People see only the records their role needs, and every sign-in is protected.

  • Role-based permissions per clinic
  • Multi-factor authentication support
  • Session timeouts and revocation
  • Quarterly access reviews
Current design

Encryption

Data is encrypted while it moves and while it is stored.

  • TLS 1.2+ for all traffic
  • Managed encryption at rest (AES-256)
  • Encrypted backups
  • Secrets kept out of source code
Current design

Network & infrastructure

The platform runs on managed US-based cloud infrastructure.

  • US data region
  • Private networking for databases
  • Managed patching by the cloud provider
  • Web traffic filtered at the edge
Pilot

Logging & monitoring

Important actions leave a trail that can be reviewed.

  • Clinical record and claim events
  • Sign-in and permission changes
  • Admin actions in the portal
  • Alerting on unusual access
Current design

Vulnerability & change management

Changes are reviewed and dependencies are scanned.

  • Peer-reviewed code changes
  • Automated dependency scanning
  • Security fixes prioritized by severity
  • Responsible-disclosure contact
Pilot

Incident response

A written plan for finding, containing and communicating incidents.

  • Triage and severity levels
  • Escalation owners
  • Customer notification assessment
  • Post-incident review
Pilot

Vendor management

Third parties that touch data are reviewed first.

  • Sub-processor register
  • Security review before onboarding
  • Data-protection terms
  • Annual re-review
Planned

Business continuity

Plans to keep clinics running if something fails.

  • Backup and restore objectives
  • Restore testing
  • Dependency failover options
  • Continuity plan review
Data handling

How your data is handled.

Plain answers about what we collect, where it lives, who can see it and what happens when you leave.

What we collect
Clinic, staff and pet-owner contact details; patient (animal) records; visit documentation; treatment estimates; claim and payment details. Collection is limited to what the clinic workflow and claim need.
Classification
Data is classed as Clinical, Financial, Personal or Operational. Each class has its own access rules, logging and retention.
Where it lives
Managed US-based cloud infrastructure. Exact residency, backup and recovery commitments are confirmed in each pilot agreement.
Who can see it
Clinic staff by role, the pet owner for their own pets, and insurers only for the claim data submitted to them. Quill staff access is limited, logged and granted for support only.
Retention & deletion
Retention periods are agreed per pilot and per data class. When retention ends, data is deleted from live systems and removed from backups as they cycle.
Leaving a pilot
Clinics can export their records in a standard format. Export, retention and deletion timelines are agreed before the pilot begins.
Sub-processors
Cloud hosting, email delivery and AI model providers. A current list is shared during diligence, and material changes are communicated in advance.
Our commitment
Quill does not sell patient, owner or clinic data, and does not share it beyond what the clinic and owner direct for care and claims.
AI governance

AI that answers to a veterinarian.

Quill's AI governance follows the NIST AI Risk Management Framework functions: govern, map, measure and manage. These are the principles every AI feature must meet.

New to these terms? See the Knowledge Hub for definitions and links to the standards.

Trust FAQ

Common questions.

Need documentation? Ask us.

We share our control mapping, policies and sub-processor list with organizations evaluating a pilot.