Security

Last updated 28 September 2026

WearableDocs is built to protect medical directives, emergency contacts, personal documents, and the evidence of every time a record is viewed. This overview describes the security architecture, encryption practices, and operational controls that protect the platform and our customers’ information.

SOC 2 Alignment

WearableDocs’ security program is mapped to the AICPA SOC 2 Trust Services Criteria for Security (Common Criteria CC1 to CC9), with selected controls also supporting Availability and Confidentiality. We are preparing for an independent SOC 2 examination.

CriteriaWearableDocs controls
Logical access CC6.1–CC6.3Salted one-way credential hashing, sign-in rate limiting, session expiry, host-locked session cookies, session revocation on credential change, and multi-factor, Zero Trust access for staff.
Boundary protection CC6.6–CC6.7HTTPS only over TLS 1.2 or higher, strict content security policy, an isolated record service, a separate administrative network address, and card data held only by Stripe.
Monitoring CC7.1–CC7.2Automated dependency alerts, nightly integrity checks with alerting, hourly external monitoring of the record service, a hash-chained access log, and logging of authentication and administrative events.
Change management CC8.1Version control, automated testing of every change, and validation in a separate staging environment before production release.
Availability A1Point-in-time database recovery, encrypted off-site backups with tested restores, durable queued processing with automatic retries, and a record service isolated from other systems.
Confidentiality C1AES-256-GCM encryption at rest, minimal data shared with service providers, and no sale of customer information.

Physical and environmental controls are inherited from Cloudflare, which maintains its own SOC 2 Type II report. WearableDocs operates the application, identity, access, development, monitoring, and customer-data controls described here.

Security Architecture

Encryption & Key Management

WearableDocs protects data in transit, at rest, and at the application layer.

LayerProtection
Data in transitHTTPS over TLS 1.2 or higher on every connection. Legacy protocols are refused.
DatabaseAES-256-GCM encryption at rest, covering live and inactive data and metadata.
Document storageAES-256-GCM encryption at rest for every uploaded document and every archived page.
Document vaultA second layer of AES-256-GCM encryption, applied by our application before a file reaches storage, under a key held only by the application service.
Record pagesAES-256-GCM encryption at rest for every published record page.
Account credentialsSalted, one-way cryptographic hashing. Passwords are never stored.
Access evidenceSHA-256 fingerprints, hash-chained per record, signed daily by an independent authority and anchored to the Bitcoin blockchain.
Off-site backupsAES-256-GCM encryption before the data leaves Cloudflare, with keys held separately from the backups.
Keys and secretsHeld in Cloudflare’s encrypted secret storage, separate from source code and customer data.

Identity & Access Control

Record Page Protection

Document Vault Protection

Evidence Integrity & Auditability

openssl cms -verify -inform DER -in root.sig -content root.bin \
    -binary -CAfile letsseal-root.crt
ots verify root.ots

How this evidence protects you if your directive is ignored.

Secure Development

Monitoring & Resilience

Privacy & Confidentiality

Responsible Disclosure

To report a security concern, email hello@wearabledocs.com.