Your choices about data
We use cookies that are required for this site to work. Anything beyond that — measuring how the site is used, or personalising what you see — happens only if you say yes.
What we do, and what we do not claim.
Certifications we do not hold are listed
Ask about your requirementsThis page is short because we will not pad it.
Compliance pages usually grow by listing frameworks a company has read about. The useful version says which obligations are actually implemented in code, which are policy, and which are neither yet. If a certification matters to your procurement, ask — the answer may be no, and you should get that answer in an email rather than after a signature.
Implemented in code
These are behaviours you can verify in a browser, not statements of intent.
Trackers firing before a choice
A consent gate that denies by default. Optional categories start off, because a pre-ticked box is not consent.Ignoring a browser opt-out signal
Global Privacy Control is honoured as a decision. A visitor broadcasting it is not asked again.Consent easy to give, hard to take back
Withdrawal reopens the choice and tears the scripts back down on the same tick.One customer seeing another's data
Tenant scoping enforced at the database, with schema-level isolation available.Accessibility as a later project
An accessibility widget ships on every surface, and the consent dialog is exempt from its restyling so it stays readable.
Not held
Listed so nobody has to infer it from silence.
SOC 2 Type II
Not held. If your procurement requires it, say so early and we will tell you honestly where that leaves us.HIPAA business associate agreement
Not offered today. Practice software handles clinical data, so this is a real question — ask before you assume either answer.ISO 27001
Not held.