Security
What we hold ourselves to — and what we do not have yet.
The public offer is a manual network segmentation assessment. This page describes its handling commitments and the website's protections. It does not establish security controls for a software platform. Agree the engagement terms before transferring any files.
Manual assessment handling
- One agreed enforcement boundary, reviewed from customer-supplied exports
- No retention of source artefacts — a firewall config and flow records are deleted within 30 days of the report, with written confirmation
- Agree the scope, handling terms and transfer method before sending assessment files
- The public contact form is for general enquiries, not patient data, credentials or assessment files
Public website protections
- Contact requests are checked for required fields and size limits before delivery
- A contact submission succeeds only when a configured delivery provider accepts it
- Application delivery logs record delivery outcomes without message contents or contact details
- Website headers are configured to block framing and content-type sniffing
What we do not have
If you are in procurement or third-party risk at a health system, this is the section you came for. We would rather you find it here than discover it in week six of a security review.
- SOC 2 Type II — no report published.
- ISO 27001 / 27017 / 27018 — not held.
- ISO/IEC 42001 — not held.
- BAA — not currently offered. Do not send PHI through this website.
- FedRAMP / StateRAMP — not in process, and we will not claim otherwise.
- External penetration test — no report or schedule published.
- Product assurance — no published SDK, signed product releases or SBOM.
- Bug bounty programme — not yet running. Report to security@guardra.ai in the meantime.
Each of these will appear on this page with the auditor, the scope and the date the moment it is real — and not one day earlier.
Reporting a vulnerability
Email security@guardra.ai. Safe harbour for good-faith research, acknowledgement within one business day, and a 90-day default disclosure window. The full policy is on the advisories page.