Security
How Chartling protects your records
Plain answers about encryption, storage, audit logs and recordings, including what we are not certified for.
What "HIPAA-aware" means here
- HIPAA covers human health records. Veterinary records are not covered by HIPAA, but your clients' names, addresses, phone numbers and payment details still deserve the same care.
- So we build Chartling to the same habits HIPAA asks for: encryption, least-privilege access, audit trails and limited retention. It is a description of how we work, not a certification.
What is encrypted
- All traffic between your browser and Chartling uses HTTPS (TLS).
- Your database, files and backups are encrypted at rest.
- Connections to payment processors, accounting tools and Google are stored encrypted on our servers and never shown in your browser.
- Card numbers go straight to Stripe or Square. Chartling never sees or stores full card numbers.
Where your data lives
- On US-based cloud infrastructure.
- Each clinic's records are kept separate. Every request checks which workspace you belong to before it reads or writes anything.
- Pet owners in the client portal only see their own household's pets, invoices and released results.
What is audit-logged
- Signing a SOAP note, with who signed and when. A note cannot be signed without the client's recorded consent for that visit.
- Controlled substance dispensing, which needs a second staff member to witness. The dispenser and witness must be different people.
- Record changes, merges, deletions and permission changes.
- Staff only see what their role allows. Owners choose what each role can do.
Exam recordings
- By default, audio is transcribed as it streams and the raw recording is never stored. Only the transcript is kept, as part of the visit record.
- A clinic can choose to keep audio until the note is signed, or for 14 or 30 days, for example to re-listen before signing.
- Nothing the AI drafts is final until a vet reviews and signs it.
Your data stays yours
- Export everything any time as CSV or Excel.
- We do not sell your data or your clients' data.
What we do not claim
- Chartling is not SOC 2 or HITRUST certified today.
- We do not sign HIPAA Business Associate Agreements, because veterinary records fall outside HIPAA.
- If your group needs a security questionnaire answered, email support@chartling.io and we will answer it plainly.
See also our privacy policy and data processing agreement.