Overview
Picardo is a health platform for managing lab results, health records, care workflows, and AI-assisted health insights. We design our systems to protect personal information and health data using administrative, technical, and organizational safeguards.
Our security program is reviewed regularly as part of our ongoing SOC 2 compliance work. We maintain internal policies and evidence in Vanta and update this page as our public security posture changes.
Data protection
- Encryption in transit: Customer-facing traffic is served over HTTPS/TLS.
- Encryption at rest: Application data and uploaded files are stored using managed providers that support encryption at rest.
- Health data handling: Picardo treats health information as sensitive data and applies heightened access, audit, and retention controls for workflows that may include PHI or ePHI.
- Data minimization: We collect and process data needed to provide the product, support customers, maintain security, and meet legal or operational obligations.
Access controls
- Access to production systems is limited to authorized team members with a business need.
- Administrative access is reviewed through our access management and compliance workflows.
- Source code changes are managed through GitHub pull requests, branch protections, and change review or documented exception workflows.
- We maintain audit logs and operational records to support investigation, access review, and compliance activities.
Infrastructure and monitoring
Picardo uses managed cloud and application services to host the product, store data, process files, send communications, and monitor system health. Our production environment includes Vercel for application hosting, Neon Postgres for the primary database, Google Cloud Storage for file storage, and Sentry for application monitoring.
- Vercel security controls, including edge protections and firewall monitoring, help protect public application traffic.
- Application alerts and error monitoring are configured to notify the team of production issues that may require investigation.
- Public availability updates are published on our status page when a material customer-facing incident occurs.
Vulnerability management
- We use dependency scanning and compliance monitoring to identify known vulnerabilities in application packages.
- Security findings are prioritized by severity and remediated through our normal code review and release process.
- Web application vulnerability scans are performed and tracked as part of our security evidence program.
Incident response
Picardo maintains incident response and breach notification procedures for suspected security events. Security issues are triaged by the responsible team members, investigated using available logs and monitoring data, and documented through our internal compliance workflow.
Customers are notified of material incidents according to our contractual, legal, and regulatory obligations.
Compliance posture
Picardo has completed a SOC 2 Type I audit. An independent auditor evaluated the design of our controls and issued our report on September 10, 2026. We continue to maintain controls aligned with healthcare data protection practices and are implementing HIPAA-aligned safeguards for workflows involving health information.
To request a copy of our SOC 2 Type I report, email security@picardo.health . Security questionnaires and vendor security reviews can be handled through our compliance process.
Security contact
To report a security concern, contact security@picardo.health . For general product support, contact support@picardo.health .