BreachClock

BreachClock Security Trust Center

Security, privacy, compliance, and assurance information for customers and prospective customers evaluating BreachClock.

Start your security review

Review public security and privacy information below, or request access to restricted materials available for customer and prospective-customer review.

Overview

Trust is earned in how we handle incident metadata, accepted clocks, and the record of what was decided — and it is easy to lose.

The BreachClock Trust Center provides security, privacy, compliance, and operational information for customers and prospective customers evaluating our hosted platform.

Controls listed as Current are in production today on Vercel and hosted Supabase. Planned items are not implied, and a listed framework is not a certification unless specifically stated.

BreachClock is built for incident metadata — discovery time, jurisdictions, encryption status, and estimated counts. It is not intended to receive patient names, medical record numbers, or other raw PHI, and it is not a HIPAA compliance certification.

Organization administrators can record in-app BAA and DPA acceptance artifacts. That record is not a substitute for a signed paper original if counsel requires one, and it is not a HIPAA certification.

Casey Morganelli

Founder and CEO, BreachClock

Product Security

Controls that are in the product today. Items not listed here are not implied.

  • Role-based access control
  • Tenant-isolated data access
  • Server-side authorization on mutations
  • No service-role key in the browser
  • Append-only activity timeline
  • Sensitive request bodies are not logged
  • Human review before clocks are accepted
  • No raw PHI fields in the data model
  • Authenticator-app multifactor authentication, including an organization-required MFA policy
  • Invite-only member join with work-email invitations
  • Minimum password length and compromised-password blocking
  • Self-serve workspace creation and Stripe-hosted billing
  • In-app support tickets
  • Counsel and internal review overlays on the rule library
  • Idle session timeout after 15 minutes of inactivity
  • Account lockout controls

Data Security

Matter records are isolated by tenant. Enter incident metadata only — discovery time, role, data types, encryption status, estimated impact, and jurisdictions. Do not enter patient names, medical record numbers, or other raw PHI.

  • Tenant-isolated database access
  • Restricted access to matters by organization membership and role
  • Incident metadata only — not patient records
  • No raw PHI fields in the data model
  • Encrypted connections in transit for hosted deployments
  • Provider-supported encryption for stored data
  • Organization export and offboarding request
  • Retention and deletion follow the customer agreement after confirmed offboardingIn progress

Compliance & Frameworks

These are frameworks and regulatory areas our customers commonly evaluate or map against. Displaying a framework here does not represent certification or attestation unless specifically stated.

HIPAA

Reference / customer mapping

HITECH

Reference / customer mapping

HITRUST

Reference / customer mapping

SOC 2

Audit planned

NIST CSF

Reference

GDPR

Privacy consideration

Documents

Public policies open immediately. Requestable materials are provided after review. Planned items are not available yet.

Vulnerability Management

BreachClock uses a layered vulnerability-management process across source code, dependencies, secrets, application security, and independent testing.

  • GitHub Dependabot for dependency alerts
  • GitHub CodeQL for static analysis
  • GitHub Secret Scanning
  • Vercel Web Application Firewall
  • Security advisories from infrastructure providers
  • Dynamic web application scanningPlanned
  • Independent third-party penetration testingPlanned

Business Continuity & Backups

Production runs on Vercel with a hosted Supabase database. Provider backups are in use. Point-in-time recovery and a published restoration drill remain planned.

  • Hosted application deployment on Vercel
  • Hosted Supabase database with provider backups
  • Application deployment resilience
  • Point-in-time recoveryPlanned
  • Documented recovery proceduresPlanned
  • Backup restoration testingPlanned

AI & Data Processing

BreachClock can draft assessment briefs from structured matter facts. A brief is decision support only. It is not a breach determination and is never auto-approved. The local demonstration provider is not a paid-plan feature.

  • Assessment briefs are generated only when a user runs them
  • AI keys stay on the server; they are not shipped to the browser
  • AI output is not treated as a decision until a person reviews it
  • Production assessments currently use the local demonstration provider and do not send matter data to a hosted model
  • Transactional email through Resend
  • Hosted AI processing by an approved providerPlanned

Risk Profile

A short view of how BreachClock treats incident metadata and privileged access.

  • Customer data is logically isolated by organization
  • Matter records are not publicly accessible
  • BreachClock is not intended for patient names or other raw PHI and is not a HIPAA certification
  • Restricted security materials are shared only through approved access
  • Public legal policies and a subprocessor list
  • Approved production subprocessors for hosting, authentication, AI, email, and billing

Reports / Assurance Materials

These are materials we can discuss with approved reviewers. A status of Planned means the artifact does not exist yet and is not available to download.

Current

  • Security OverviewAvailable on request
  • Architecture OverviewAvailable under NDA
  • Access Control ModelAvailable on request
  • Backup OverviewAvailable on request
  • Encryption OverviewAvailable on request
  • In-app BAA and DPA acceptanceAvailable on request

Planned

  • Third-Party Penetration Test SummaryPlanned
  • SOC 2 Type II ReportPlanned

Request restricted materials

Restricted security materials may be provided to current customers and qualified prospective customers after review. Certain materials may require NDA acceptance. Requests are not approved automatically.

Cookies

We use essential cookies to operate BreachClock, including sign-in and security. Optional analytics cookies help us understand how the public website is used. Block all turns off optional cookies. Essential cookies still run because the site cannot work without them. See the Cookie Policy.