Vetch for multi-location practices is now in private beta · Join the waitlist →
VetchVetch
Legal

Trust & Security

Veterinary clinics trust Vetch with the medical record. We treat that responsibility the way the most regulated parts of healthcare do — encryption, audit logs, third-party attestations, and a security team you can email.

Last updated: May 8, 2026

Certifications and frameworks

SOC 2 Type IIIndependently audited annually. Report available under NDA via our trust portal.
UK GDPR / DPA 2018UK Information Commissioner's Office (ICO) is our supervisory authority. UK IDTA and EU SCCs on file for transfers.
Cyber Essentials PlusUK government-backed scheme — certification in progress, targeted Q3 2026.
PCI DSSPayments handled by Stripe (PCI Level 1). Vetch never stores raw card data.
ISO 27001Roadmap target for 2026; controls already mapped in our ISMS.

Encryption

Access controls

Monitoring and incident response

Application security

AI safety

Backups, recovery, and continuity

Sub-processors

See /legal/dpa for the current sub-processor list and notification process.

Reporting a vulnerability

Report security issues to security@vetch.vet. We acknowledge within one business day and don’t pursue legal action against good-faith researchers who follow our coordinated-disclosure guidelines (do not access customer data, don’t run DoS, give us reasonable time to fix).

Contact

Security questions or attestations: security@vetch.vet. Trust portal access on request.