The chart is yours. The keys, the logs, and the kill-switch — also yours.
Vetch runs the regulated parts of veterinary practice on infrastructure built for regulated environments. Encryption you'd expect, audit you can read, AI you can rein in.
Six things you should be able to see, control, and prove.
Encrypted end to end
TLS 1.2+ in transit, AES-256 at rest. AWS KMS for key management; customer-managed keys on Group plans.
Every action attributed
Every action — Vetch or human — is timestamped, attributed, and exportable. Admin-accessible, filterable, no silent edits.
Right people, right rooms
SSO via SAML/OIDC, mandatory MFA, role-based access down to the field level. Quarterly access reviews; same-day de-provisioning.
Vetch you can rein in
Off / Suggest / Ask / Auto — per-clinic, per-capability. High-stakes actions (controlled-substance signing, charging cards, external messages) always pause for a human.
Exportable, always
Charts, financials, recall queues — clean CSV/PDF exports, free, no questions. We earn the renewal every year, not by holding data hostage.
Ready when it isn’t
24/7 on-call, 72-hour customer breach notification, RPO 5 min / RTO 4 hr, quarterly DR drills. A plan that’s rehearsed, not printed.
Aligned to the frameworks that matter.
We follow the regulated-healthcare playbook — third-party attested, BAA-ready, and honest about what's audited today vs. what's on the roadmap.
- SOC 2 Type II — independently audited annually. Report under NDA via the trust portal.
- UK GDPR / DPA 2018 — the ICO is our supervisory authority. UK IDTA and EU SCCs on file.
- Cyber Essentials Plus — UK government-backed scheme; certification in progress, Q3 2026 target.
- PCI DSS — payments handled by Stripe (PCI Level 1). Vetch never stores raw card data.
- ISO 27001 — controls already mapped in our ISMS; certification target is 2026.
Honest answers.
Trust isn’t a banner. It’s the way the system runs.
See the architecture in 30 minutes — book a walkthrough with our security team on the call.