Snapshot 17136
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security and Compliance at Botdoc Botdoc moves regulated documents for banks, healthcare systems, schools, and dealerships. Our security posture is examined annually and documented for customer review. Quick links: Independent Examination Encryption Infrastructure Regulatory Alignment Access and Authentication Monitoring and Testing Verify Us Report Issues Independent Examination Botdoc's controls are examined annually under SOC 2 Type 2 (Security Trust Services Criteria). Our most recent report covers the full 2025 calendar year with a clean, unqualified opinion. The report and our 161-control vendor risk assessment, mapped to the NIST Cybersecurity Framework, are available to customers and partners under NDA. Encryption Documents are encrypted in transit with TLS and at rest with AES-256, under per-transaction keys generated and stored in Azure's hardened key store, where no person can view them. There is no master key. Data is purged automatically after the delivery window. Infrastructure Botdoc runs on Microsoft Azure, which maintains its own ISO/IEC 27001 certification and independent attestations. Botdoc's application-layer controls are examined separately under our SOC 2 program. Regulatory Alignment GLBA / FTC Safeguards Rule. Encryption of customer information in transit, access controls, monitoring, and service-provider oversight. HIPAA. Safeguards for ePHI in transit with audit controls and minimum-necessary access. PCI DSS. Compliant as service provider and merchant. GDPR and FERPA. Control framework designed for compliance; documentation available on request. EU-U.S. Data Privacy Framework. Botdoc aligns its cross-border data handling with the EU-U.S. Data Privacy Framework principles. Access and Authentication Multi-factor authentication is enforced on production systems and employee accounts. Single sign-on is supported via Auth0, with Okta integration available. Access follows least privilege with logged administrative activity. Monitoring and Testing Continuous 24x7 monitoring with independent weekly vulnerability scanning. We maintain a public vulnerability disclosure policy and welcome good-faith security research: botdoc.io/our-terms/vulnerability-disclosure/. Botdoc is a CISA Secure by Design pledge signatory. Verify Us Request the compliance portfolio (SOC 2 Type 2 report, vendor risk assessment, policies, insurance certificate) through your account contact or [email protected]. Right to audit is granted to clients and their member associations. Report Issues System failures, suspected incidents, or general issues: [email protected]. Suspicious or fake emails: forward the entire email, including header information, to [email protected], then delete it from your mailbox. Unethical behavior: [email protected]. Updates and Alerts Routine maintenance, new features, fixes, updates and other important announcements appear on the Botdoc blog. View the latest updates and announcements on the Botdoc blog →