Vetch for multi-location practices is now in private beta · Join the waitlist →
VetchVetch
Legal

Trust & Security

Veterinary clinics trust Vetch with the medical record. We treat that responsibility the way the most regulated parts of healthcare do — encryption, audit logs, third-party attestations, and a security team you can email.

Last updated: May 8, 2026

Certifications and frameworks

SOC 2 Type IIIndependently audited annually. Report available under NDA via our trust portal.
HIPAABAA available for US customers. Aligned to HIPAA Security and Privacy Rules.
GDPR / UK GDPREU and UK Standard Contractual Clauses, transfer impact assessment, EU data residency on Group plans.
PCI DSSPayments handled by Stripe (PCI Level 1). Vetch never stores raw card data.
ISO 27001Roadmap target for 2026; controls already mapped in our ISMS.

Encryption

Access controls

Monitoring and incident response

Application security

AI safety

Backups, recovery, and continuity

Sub-processors

See /legal/dpa for the current sub-processor list and notification process.

Reporting a vulnerability

Report security issues to security@vetch.vet. We acknowledge within one business day and don’t pursue legal action against good-faith researchers who follow our coordinated-disclosure guidelines (do not access customer data, don’t run DoS, give us reasonable time to fix).

Contact

Security questions or attestations: security@vetch.vet. Trust portal access on request.