Standard Form Inc. builds scheduling software for residency programs and physician groups. This page describes how we protect the data you put into the Service, where that data lives, which other companies touch it, and how to tell us about a security problem.
Our trust center is at trust.heystandard.com. Current compliance documentation will be published there.
1. Compliance Status
We are working toward SOC 2 Type II. That work is in progress. We do not have a SOC 2 report today, and we will not say otherwise until an auditor has issued one.
We hold no other security certification. We are not making a HIPAA claim. The platform is not built to process protected health information, and we ask customers not to put it there.
If your procurement process needs documentation we do not yet have, write to founders@heystandard.com and we will tell you plainly what exists and what does not.
2. What Data We Hold
The platform holds the information needed to build a schedule:
- Names, email addresses, phone numbers, and ranks of the people on your schedule
- Their assignments, leave dates, and stated preferences
- The blocks, coverage requirements, and rules you write
- Account identities: email addresses, hashed passwords, and session tokens
It does not hold patient records, clinical notes, or protected health information, and it does not connect to an electronic health record. The full scope of the product, including its limits, is documented at docs.heystandard.com.
3. Encryption
3.1 In transit. Connections to the web application, the API, and the database are encrypted with TLS.
3.2 At rest. Customer data at rest is encrypted by the infrastructure providers listed in section 5, using platform-managed encryption and provider-held keys. Standard Form does not operate its own key management.
3.3 Secrets. Application credentials are held in each provider's managed secrets store, Supabase, Vercel environment variables, Modal secrets, and AWS Secrets Manager, and never in source code. Our repositories are scanned for committed secrets on every change.
3.4 Company devices. Engineering laptops may hold cached debug exports and local database dumps for the duration of an active debugging session. Full-disk encryption is enforced on those devices through device management, and that material is treated as ephemeral rather than retained.
4. Where Data Is Hosted
The Service runs in the United States.
- Customer production data and user identities are stored in Supabase (Postgres and Auth). Both the primary database and its backups are in us-west-1, Northern California, United States.
- The web applications are hosted on Vercel. Serverless functions run in iad1, Washington DC, United States. Cached content is distributed. Vercel runtime logs may contain person identifiers that appear in request URLs.
- The scheduling solver and the assistant's working state run on Modal. The solver itself is stateless and persists no customer data. Assistant workspace state is held in Modal volumes. Modal container placement is constrained to United States regions. Function inputs and outputs are routed through Modal's servers in Virginia, United States.
5. Subprocessors
These companies process customer data on our behalf:
- Supabase. Database and authentication. United States.
- Vercel. Application hosting and runtime logs. United States.
- Modal. Solver execution and assistant workspace state. Distributed.
- Anthropic. The language model behind Puffin, our scheduling assistant. Prompts may include schedule context and the names or identifiers of people on your schedule. Storage is in the United States. Anthropic deletes API inputs and outputs after 30 days by default; longer retention applies only to content flagged by trust and safety review. We have not activated zero-data-retention, so the default applies. As stated in our Privacy Policy, your data is not used to train external AI models.
- PostHog. Product analytics and feature flags. Events may include person and schedule identifiers. United States, AWS us-east-1. Event data retained for one year.
- Sentry. Error reporting. Reports may include stack traces and request context. United States, Google Cloud. Retained for 30 days.
These corporate systems may hold customer contact information, but hold no schedule data:
- Google Workspace. Company email, documents, and calendar. United States.
- Attio. Customer relationship records. Google Cloud, Ireland. Personal data may transfer to United States subprocessors under standard contractual clauses.
- Notion. Internal documentation and planning notes. United States.
- Linear. Engineering tickets, which may include customer-context snippets. United States.
- GitHub. Source code, commit history, and CI configuration. Holds no customer production data. United States.
We also hold a corporate AWS account. It has no active workloads and stores no customer data.
We will update this page before adding a subprocessor that processes customer data.
6. Retention and Deletion
Customer production data in Supabase is retained for the life of the customer contract plus three years. Retention at each subprocessor is governed by that provider's plan; the periods we track are recorded in our internal data inventory and summarized in section 5 where they are short enough to matter.
To request deletion of your data, contact founders@heystandard.com.
7. Access
Standard Form has two employees. Both hold accounts on the systems above, with administrative access granted only where the role requires it. Production data access is not granted by default, and local copies of production data are treated as ephemeral. Multi-factor authentication is required on every system that supports it, and account access is reviewed on a quarterly cycle.
8. Reporting a Vulnerability
Email founders@heystandard.com. Please include:
- What you found, and where
- The steps to reproduce it
- What an attacker could do with it
We aim to acknowledge your report within 3 business days, and will keep you updated while we work on a fix.
While researching, please do not run automated scanning against production, access or modify data that is not yours, degrade the service for other users, or use social engineering against our staff or customers. If you follow that and report in good faith, we will not pursue legal action over your research.
We do not run a paid bug bounty program.
9. Questions
For security questionnaires, subprocessor questions, or anything else on this page:
Email: founders@heystandard.com
Company: Standard Form Inc.
Location: United States of America
