Last updated July 28, 2026

Security

What protects your account and your records, plus a list at the bottom of what we have not done yet.

Passwords and sessions

Passwords are hashed with scrypt and a per-user random salt. We cannot read your password, and a database disclosure would not reveal it.

Session tokens are signed with HMAC-SHA256 and carry a version claim derived from your password hash. Changing your password invalidates every outstanding session immediately, everywhere. Cookies are HTTP-only, same-site, and secure in production.

Access control

Every read and every write is checked against the signed-in user's ownership of the clinic in question, on the server, on every request. There is no client-side gate to bypass and no shared identifier that lets one account address another's records.

Record integrity

Attestations, hour entries, and signed protocol versions are append-only. No update or delete path for them exists in the application — not for you, not for support, not for an administrator. Timestamps come from the server clock at the moment of creation and cannot be supplied by the browser.

Entries recorded after the documentation window are stored with their true creation date and displayed with a visible late-entry label, matching ordinary medical-record convention. We do not offer backdating.

Protocol versions carry a uniqueness constraint at the database level, and each attestation binds the protocol versions in force at signing time, derived on the server rather than accepted from the browser.

Data in transit and at rest

All traffic is served over HTTPS. The database is stored on our hosting provider's managed, encrypted disks and backed up on a regular schedule.

Payments

Card data is handled entirely by Stripe, a PCI Level 1 service provider. Card numbers never reach our servers. Webhooks from Stripe are signature-verified and processed idempotently, so a replayed or forged callback cannot change your subscription state.

What we have not done yet

No SOC 2 report. We are a small operation and have not completed a SOC 2 Type II audit. If your procurement requires one, we are not yet the right vendor.

No two-factor authentication yet. It is planned. Until it ships, use a long unique password from a password manager.

No formal penetration test. The application has been reviewed and tested internally but has not been assessed by an independent third party.

No HIPAA certification exists— for anyone. “HIPAA certified” is not a real status, and any vendor claiming it should worry you. We will sign a BAA on request; see the Privacy Policy for how we handle chart identifiers.

Reporting a vulnerability

Email security@standingmd.com with enough detail to reproduce the issue. We will acknowledge within 3 business days. We will not pursue legal action against anyone who reports in good faith, avoids privacy violations and service disruption, and gives us reasonable time to fix it before disclosing.