Trust

Security practices

What we actually have in place today, stated plainly — including what we don't have yet.

Local-first architecture

Most tools process files locally in your browser by default and never send the file to our servers. The Vault and Document Reminders are separate, clearly labeled features that do involve server-side storage — see how files are handled for the specifics of each tool.

Access controls

Customer records are protected with database row-level security and organization-membership checks in addition to application authorization. Authorized teammates in the same organization can intentionally work from shared records; users outside that organization are not granted that same access through the customer Data API. Sensitive server operations also perform their own authorization checks. Connections use HTTPS/TLS in transit.

Audit logging

Database triggers record Vault-file and Reminder creation and deletion so those events do not depend on one application screen remembering to log them. Expoalb also records selected sensitive application actions, including organization and platform-admin decisions and customer data exports. We do not currently claim that every record view or every action in the product is captured in a universal access log.

What we don't have yet

  • No formal compliance certification. We are not currently HIPAA certified, SOC 2 audited, or similarly certified by a third party. The practices above are real, in-place technical controls — not a substitute for formal certification, which we'd pursue once customer needs justify the cost of a formal audit.
  • No signed Business Associate Agreements (BAAs) with our infrastructure providers at this time. If you need a BAA for regulatory reasons, contact us before storing protected health information in the Vault.
  • The Sign tool produces a visual signature image, not a timestamped, audit-trailed e-signature meeting ESIGN Act or eIDAS requirements.

Questions about our security practices: andi@expoalb.com