Overview
Trust is earned in how we handle incident metadata, accepted clocks, and the record of what was decided — and it is easy to lose.
The BreachClock Trust Center provides security, privacy, compliance, and operational information for customers and prospective customers evaluating our hosted platform.
Controls listed as Current are in production today on Vercel and hosted Supabase. Planned items are not implied, and a listed framework is not a certification unless specifically stated.
BreachClock is built for incident metadata — discovery time, jurisdictions, encryption status, and estimated counts. It is not intended to receive patient names, medical record numbers, or other raw PHI, and it is not a HIPAA compliance certification.
Organization administrators can record in-app BAA and DPA acceptance artifacts. That record is not a substitute for a signed paper original if counsel requires one, and it is not a HIPAA certification.
Casey Morganelli
Founder and CEO, BreachClock