Security & Compliance
Klaxar is committed to the highest standards of data security for public safety agencies. We are actively pursuing SOC 2 Type I certification, targeting a Q1 2027 report date.
SOC 2 Type I โ In Progress
Klaxar has engaged a licensed CPA firm for SOC 2 Type I examination. The audit evaluates our security controls against the AICPA Trust Services Criteria: Security, Availability, Confidentiality, Privacy, and Processing Integrity.
Expected report date: Q1 2027 ยท Audit firm: TBD ยท Scope: Production Klaxar platform
Security Controls
- โ99.9% uptime SLA target
- โDigitalOcean managed infrastructure with auto-restart
- โPM2 process monitoring with alerting
- โAutomated daily database backups
- โAES-256 encryption at rest (Supabase)
- โTLS 1.3 in transit
- โRow-level security (RLS) on all PHI tables
- โService role key never exposed to client
- โHIPAA-grade audit log on all PHI access
- โRole-based access control (RBAC)
- โMulti-factor authentication support
- โAPI rate limiting on all endpoints
- โDependency vulnerability scanning (npm audit)
- โBAA (Business Associate Agreement) available
- โData residency: US-only (DigitalOcean NYC)
- โRight to access / deletion (HIPAA ยง164.524)
- โBreach notification procedures
- โAutomated TS + lint CI on all PRs
- โAI billing outputs always reviewed by human
- โAudit trail on claim status changes
Certification Timeline
Security policy documentation
Internal audit & gap assessment
Penetration test ($5-15K, external firm)
SOC 2 Type I audit engagement
SOC 2 Type I report issued
SOC 2 Type II audit (12-month observation)
HIPAA Compliance
Klaxar is designed as a HIPAA-covered entity platform. All PHI is processed under strict access controls, audit logging, and data isolation policies.
- โBusiness Associate Agreements (BAA) available for all paid plans
- โAll patient data stored on HIPAA-eligible infrastructure (Supabase BAA tier)
- โComprehensive audit log for all PHI access events
- โRole-based access enforced via Supabase RLS on all PHI tables
Security questions or to request our BAA? Contact our security team or email security@klaxar.com.