Vetch for multi-location practices is now in private beta · Join the waitlist →
VetchVetch
Legal

Trust & Security

Veterinary clinics trust Vetch with the medical record. We treat that responsibility the way the most regulated parts of healthcare do — encryption, audit logs, role-based access, and a security team you can email.

Last updated: May 8, 2026

Frameworks and compliance

SOC 2Controls implemented and operating, mapped to the Trust Services Criteria. Independent Type II audit is on our roadmap; the report will be available under NDA once complete.
UK GDPR / DPA 2018UK Information Commissioner's Office (ICO) is our supervisory authority. UK IDTA and EU SCCs on file for transfers.
Cyber Essentials PlusUK government-backed scheme — on our certification roadmap.
PCI DSSPayments handled by Stripe (PCI Level 1). Vetch never stores raw card data.
ISO 27001On our certification roadmap; controls already mapped in our ISMS.

Encryption

Access controls

Monitoring and incident response

Application security

AI safety

Backups, recovery, and continuity

Sub-processors

See /legal/dpa for the current sub-processor list and notification process.

Reporting a vulnerability

Report security issues to security@vetch.vet. We acknowledge within one business day and don’t pursue legal action against good-faith researchers who follow our coordinated-disclosure guidelines (do not access customer data, don’t run DoS, give us reasonable time to fix).

Contact

Security questions or documentation: security@vetch.vet. Trust portal access on request.