Security, data handling and AI governance.
Veterinary clinical, financial and personal data deserves layered protection. This Trust Center explains the controls behind QuillsFlow, mapped to the AICPA SOC 2 Trust Services Criteria. Each control is labeled as current design, pilot, or planned.
Mapped to the SOC 2 Trust Services Criteria.
SOC 2 is the AICPA framework for how service providers protect customer data. We use its criteria as the standard for the Quill application and supporting systems. An independent SOC 2 audit is planned; no report has been issued yet.
Tap or click a criterion to pin its details; tap it again or use Reset to return to the overview. Arrow keys move between criteria, Esc resets.
Showing CC1: Control environment. Who is accountable for security and how expectations are set.
CC1 · Control environment
Current designWho is accountable for security and how expectations are set.
- Named security owner and leadership review
- Acceptable-use and confidentiality agreements for staff
- Security responsibilities written into role descriptions
Quill implementation detail
- Security owner reviews access, incidents and vendor changes on a set cadence
- All staff and contractor accounts sign confidentiality terms before platform access is provisioned
- Engineering, support and clinical-review responsibilities are separated so no single role can change data unreviewed
Quill's commitment: veterinary clinical, financial and personal data is protected by layered technical controls — encryption in transit and at rest, per-clinic data isolation, logged access and reviewed changes. Controls are mapped to the AICPA SOC 2 Trust Services Criteria; an independent audit is planned and no report has been issued yet.
Eight control families.
Each family starts with what it means for your clinic, followed by the specific controls.
Identity & access
People see only the records their role needs, and every sign-in is protected.
- Role-based permissions per clinic
- Multi-factor authentication support
- Session timeouts and revocation
- Quarterly access reviews
Encryption
Data is encrypted while it moves and while it is stored.
- TLS 1.2+ for all traffic
- Managed encryption at rest (AES-256)
- Encrypted backups
- Secrets kept out of source code
Network & infrastructure
The platform runs on managed US-based cloud infrastructure.
- US data region
- Private networking for databases
- Managed patching by the cloud provider
- Web traffic filtered at the edge
Logging & monitoring
Important actions leave a trail that can be reviewed.
- Clinical record and claim events
- Sign-in and permission changes
- Admin actions in the portal
- Alerting on unusual access
Vulnerability & change management
Changes are reviewed and dependencies are scanned.
- Peer-reviewed code changes
- Automated dependency scanning
- Security fixes prioritized by severity
- Responsible-disclosure contact
Incident response
A written plan for finding, containing and communicating incidents.
- Triage and severity levels
- Escalation owners
- Customer notification assessment
- Post-incident review
Vendor management
Third parties that touch data are reviewed first.
- Sub-processor register
- Security review before onboarding
- Data-protection terms
- Annual re-review
Business continuity
Plans to keep clinics running if something fails.
- Backup and restore objectives
- Restore testing
- Dependency failover options
- Continuity plan review
How your data is handled.
Plain answers about what we collect, where it lives, who can see it and what happens when you leave.
- What we collect
- Clinic, staff and pet-owner contact details; patient (animal) records; visit documentation; treatment estimates; claim and payment details. Collection is limited to what the clinic workflow and claim need.
- Classification
- Data is classed as Clinical, Financial, Personal or Operational. Each class has its own access rules, logging and retention.
- Where it lives
- Managed US-based cloud infrastructure. Exact residency, backup and recovery commitments are confirmed in each pilot agreement.
- Who can see it
- Clinic staff by role, the pet owner for their own pets, and insurers only for the claim data submitted to them. Quill staff access is limited, logged and granted for support only.
- Retention & deletion
- Retention periods are agreed per pilot and per data class. When retention ends, data is deleted from live systems and removed from backups as they cycle.
- Leaving a pilot
- Clinics can export their records in a standard format. Export, retention and deletion timelines are agreed before the pilot begins.
- Sub-processors
- Cloud hosting, email delivery and AI model providers. A current list is shared during diligence, and material changes are communicated in advance.
- Our commitment
- Quill does not sell patient, owner or clinic data, and does not share it beyond what the clinic and owner direct for care and claims.
AI that answers to a veterinarian.
Quill's AI governance follows the NIST AI Risk Management Framework functions: govern, map, measure and manage. These are the principles every AI feature must meet.
New to these terms? See the Knowledge Hub for definitions and links to the standards.
Common questions.
Need documentation? Ask us.
We share our control mapping, policies and sub-processor list with organizations evaluating a pilot.