Skip to main content

Security & trust

Security, without the badges we haven’t earned.

Where data lives, how it’s encrypted, who can access what, and what we’re still working on. No badges we haven’t earned. Procurement teams: this is the page to send to your security reviewers.

Where is data physically stored?

Production infrastructure runs on AWS, with imaging media held in encrypted cloud object storage. If your organisation has specific data-residency requirements, talk to us before procurement — we’ll give you a straight answer about what we can support today.

How is data encrypted?

In transit: TLS across every endpoint. At rest: AES-256 encryption for DICOM studies, scope videos, reports, and supporting documents.

Who can access what?

Access is role-based and scoped to the sale a record belongs to. A vet at Clinic A can’t see a horse submitted by Clinic B unless explicitly shared by the sale admin or the consignor. Sale-company administrators see only horses for sales they configure.

Is there an audit trail?

Yes. Every submission, approval, edit, view, and notification is logged with actor, timestamp, and resulting state. Sale-company admins can review the audit trail for any sale they configure.

What's the backup and disaster-recovery posture?

Databases are backed up daily with point-in-time recovery, and imaging media is stored redundantly. If your procurement process needs specific recovery-time commitments, ask us — we’d rather agree them with you directly than publish numbers here.

How do you handle GDPR / data-subject requests?

Personal data (vet names, consignor contacts, audit log identifiers) is treated as Article 4 (1) personal data. For data-subject access, rectification, or erasure requests, contact support@thoroughvet.com.

What certifications do you hold?

Honest answer: none yet that we’ll claim on this page. We’d rather publish nothing than publish a badge we don’t deserve. If you need a specific certification before procurement signs, talk to us about timing.

How do I report a vulnerability?

Email support@thoroughvet.com with reproduction steps and we’ll get it to the right people. We don’t run a paid bug bounty programme.

What happens during an incident?

On detection, the on-call team is paged immediately and affected customers are notified. Sale-day incidents during major bloodstock sales are prioritised and tracked separately — the support team is on-call through sale week.

Can I export my data?

Sale companies retain ownership of their repository data — original DICOM, scope videos, and vet reports — and can request a complete export. No vendor lock-in.