Every control, with its true status.
This page lists what protects incident records, and marks each control live, rolling out or planned.
| Control | What it does | Status |
|---|---|---|
| Access | ||
| One-time-code sign-in | Reviewers and managers sign in with a code sent to their email. No shared passwords. | Live |
| Role-based access | Six roles, from reporter to read-only auditor. Each sees only what its role needs. | Live |
| Single sign-on (SAML/OIDC) | For Network plans. Roles map from your identity provider. | Live |
| Reporter links without accounts | Each link covers one site, is rate limited and cannot read other reports. | Live |
| Data | ||
| Encryption in transit | TLS on every connection to the app and the API. | Live |
| Encryption at rest | The hosting provider encrypts the database and file storage. | Live |
| Organization isolation | Every record belongs to one organization. Every query filters by it. | Live |
| Retention controls | Retention periods per site, plus legal hold, on Regulated and Network. | Rolling out |
| Export and deletion | Full CSV and PDF export on every plan. Deletion on request. | Live |
| Audit and proof | ||
| Append-only audit trail | Logs who changed what and when, for every field. The AI-draft mark stays until a person approves. | Live |
| Signed webhooks | Every event carries an HMAC signature. Replayed events are rejected. | Live |
| Read-only auditor access | Give a surveyor or insurer a time-limited, read-only view of a packet. | Rolling out |
| AI safeguards | ||
| A person signs | Lauren drafts. Nothing is final until a named person approves it. | Live |
| BAA-covered AI provider | On Regulated and Network, Lauren's provider signs a BAA and does not train on your data. | Live |
| No patient information on Open | The free plan blocks patient identifiers and tells the reporter why. | Rolling out |
| Prompt and output logging | AI inputs and outputs go to the audit trail for review. | Live |
| Operations | ||
| Backups and a restore drill | Automated backups, plus a documented restore test before launch. | Live |
| Dependency and secret scanning | Automated checks run on every change. | Live |
| Vulnerability disclosure | A security.txt file and a monitored security mailbox. | Live |
| Third-party penetration test | An independent test. A summary will be available under NDA. | Planned |
| SOC 2 Type II | We are scoping the audit. No certification today; we will publish the report when done. | Planned |
A team summary, not an audit report. The changelog records when statuses change.
Get the details your reviewer needs.
Usually sent within one business day.
- How data flows, including where AI is called.
- Sub-processor list with purpose and region.
- BAA overview, and who is responsible for what.
- Answers to a standard questionnaire, mapped to the HIPAA Security Rule.
Security, answered.
Something we missed? Ask us, and a person answers.
Do you sign a BAA?
Yes, on Regulated and Network. The BAA covers the app and the AI provider that processes incident text. Read how we approach HIPAA or request the security packet.
Are you SOC 2 certified or HIPAA certified?
No, and we say so plainly. HIPAA has no official certification, so be wary of any vendor that claims one. SOC 2 is planned. Today we can show the control table, the audit trail and the BAA.
Is patient information used to train AI models?
No. On Regulated and Network, the AI provider has a BAA and may not train on your data. On Open, patient data is not allowed in reports.
Where is data stored?
In the United States, on a major cloud provider. The security packet names the provider, region and sub-processors.
How do I report a vulnerability?
Email security@incidentkit.ai. Our security.txt has the contact and our disclosure policy. We acknowledge reports within two business days.
Does this website send patient information to analytics?
No. This website is not built to receive patient data. Form fields are masked in session replay, and analytics run only after consent. See the privacy policy and cookie policy.
Review the controls, then see the product.
Create your kit in about ten minutes and report the first incident the same day. Free to start, no card.