Announcements

Compliance & Security at Webstrail

Published on Aug 25, 2023

Welcome to our Trust Center! Webstrail views Security & Compliance as the foundation upon which our products are built, as well as how trust with our customers is earned and maintained. Webstrail uses Vanta to continuously monitor its internal security controls against the highest possible standards. Vanta provides us with real-time visibility across the organization to ensure the end-to-end security and compliance posture of our systems.

HIPAA

Webstrail continually monitors HIPAA through assessments and controls, which serves as validation of our dedication and adherence to the highest security standards for working with Patient Health Information (PHI). We provide our customers with the peace of mind that we are proactively protecting their PHI and adhering to HIPAA regulations.

SOC 2

SOC 2 is an extensive auditing procedure that ensures that a company is handling customer data securely and in a manner that protects the organization as well as the privacy of its customers. Receiving SOC 2 attestation in 2024 was an important milestone in showing our commitment to our customers and the security of their data.

Compliance

Documentation of our compliance against global standards including certifications, attestations, and audit reports.

SOC 2 Web Application Penetration Test
SOC 2 Web Application Penetration Test
HIPAA
HIPAA
SOC 2 Type 2 Attestation Report
SOC 2 Type 2 Attestation Report

Continuous monitoring

Data Security

Daily Database Backups
Databases Monitored and Alarmed
Logging/Monitoring

Infrastructure Security

Quarterly External Vulnerability Scans
Quarterly Internal Vulnerability Scans

Organization Security

Acceptable Use Policy
Accepting the Terms of Service
Business Associate Agreements
Incident Response Plan
Maintaining a Terms of Service
MFA on Accounts
Security Policies
Security Training

Network Security

Denial of Public SSH
Firewalls

Product Security

Annual Penetration Tests
Code Review Process
Disaster Recovery Plan
Quarterly Vulnerability Scan
Software Development Lifecycle