TinyDocx Trust Center

We will always take care of each other.

Back to tinydocx.com →

Security, compliance, and privacy documentation for TinyDocx.

SOC 2 Type I · Report Available HIPAA BA · Examination Complete System · Operational

Page last reviewed 21 August 2026.

AICPA SOC for Service Organizations logo

Compliance Posture

SOC 2 Type I Report Issued Request report →
HIPAA Business Associate Examination Complete Request report →
SOC 2 Type II Planned Details →

Both examinations were performed by Johanson Group LLP, an independent licensed CPA firm, as of June 15, 2026. Each received an unqualified opinion. A SOC 2 Type II examination is planned to follow.

Insurance

Coverage Carrier Limits Policy period
Commercial General Liability Hiscox $1,000,000 each occurrence
$2,000,000 general aggregate
1 May 2026 – 1 May 2027
Professional Liability (E&O) Hiscox $1,000,000 each claim
$1,000,000 aggregate
1 May 2026 – 1 May 2027
Cyber Liability Hiscox On the certificate of insurance On the certificate of insurance

Cyber Liability coverage includes breach response costs, cyber extortion, cyber crime, business interruption, data recovery, and privacy protection.

Certificates of insurance. A COI naming your entity as certificate holder, or as additional insured where your agreement requires it, is available from security@tinydocx.com. We will respond within two business days. Policy numbers are not published; they appear on the certificate.

Audit Reports

SOC 2 Type I — Security
Auditor
Johanson Group LLP, independent licensed CPA firm
Opinion
Unqualified
Criteria
Trust Services Criteria — Security
Systems in scope
MemoryBook and Mermaid Sea
As of
June 15, 2026 (point in time)
Report issued
August 10, 2026
HIPAA Business Associate — Report on Compliance
Auditor
Johanson Group LLP, independent licensed CPA firm
Opinion
Unqualified
Framework
HHS HIPAA Audit Program — Security and Breach Notification Rule protocols
Systems in scope
MemoryBook and Mermaid Sea
As of
June 15, 2026 (point in time)
Report issued
August 14, 2026
How to request a report. The SOC 2 report is a restricted-use document under AICPA attestation standards and is not published publicly. It is available to customers, prospective customers, business partners, and their advisors, under NDA. Email security@tinydocx.com and we will respond within two business days.

A Type I report addresses the suitability of the design of controls at a point in time. It does not address operating effectiveness over a period, which is the subject of a Type II examination. The HIPAA examination does not constitute a legal determination of compliance.

What the Reports Cover

Within the audited boundary
  • MemoryBook
  • Mermaid Sea
Outside the audited boundary
  • Hash Browns, the MUE Dictionary, and the DMEPOS fee-schedule pricer
  • Senior Tree
  • This trust center, the marketing site, and the status page

The excluded products serve machine-executable encodings of published regulatory reference material. They are free of protected health information by design and process no customer application data.

Data Handling

Data we process
  • Document content uploaded by customers
  • Account metadata (email, organization, billing)
  • Usage telemetry
Data we do not process
  • Payment card data
  • Protected health information (see PHI status below)
  • Biometric data
  • Children's data
PHI status. Through September 14, 2026, TinyDocx does not create, receive, maintain, or transmit protected health information in any system. This is stated in management's assertion within the SOC 2 report. The HIPAA framework — the Business Associate Agreement template, breach notification policy and reporting forms, and deletion procedure — operates as a readiness control set until the September 2026 cutover, at which point HIPAA-eligible vendor tiers with executed Business Associate Agreements are provisioned before any PHI is processed. With respect to Covered Entity customers, TinyDocx acts as a Business Associate. TinyDocx is not itself a Covered Entity.

Subprocessors

View full list →
Amazon Web Services
Production infrastructure and data center hosting
us-east-1
Auth0 (Okta, Inc.)
Customer identity and access management
US
Google Workspace (Google LLC)
Corporate email and identity
US
GitHub
Source code hosting and CI
US
Vanta
Compliance monitoring
US
Anthropic
Internal engineering assistance; no customer data or PHI
US

AWS is treated as a carve-out subservice organization in the SOC 2 report. Subprocessors are reviewed annually under the vendor management program, including review of their available attestation reports. Customers are notified at least 30 days before a new subprocessor begins processing their data, in accordance with the applicable Data Processing Agreement.

FAQ

Where is TinyDocx data hosted?
TinyDocx hosts all customer data on Amazon Web Services in the United States (us-east-1).
Can I see your SOC 2 report?
Yes, under NDA. The SOC 2 report is a restricted-use document under AICPA attestation standards, so it is not posted publicly. It is available to customers, prospective customers, business partners, and their advisors. Email security@tinydocx.com and see Audit Reports for what the report covers.
What do the audit reports cover?
Both examinations cover MemoryBook and Mermaid Sea as of June 15, 2026. The SOC 2 is a Type I examination against the Security trust services criteria, addressing the suitability of the design of controls at that date rather than their operating effectiveness over a period. The HIPAA examination covers the Security and Breach Notification Rule protocols of the HHS HIPAA Audit Program. Both received unqualified opinions. Hash Browns, the MUE Dictionary, the DMEPOS pricer, and Senior Tree fall outside the audited boundary.
How is data encrypted?
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
Does TinyDocx use customer data to train AI models?
No. TinyDocx never uses customer data to train AI models.
Can I sign a Business Associate Agreement (BAA)?
Yes. With respect to Covered Entity customers, TinyDocx acts as a Business Associate. PHI processing begins at the September 2026 cutover; a BAA executed before then takes effect at that point. Email security@tinydocx.com to request one.
How do I report a security vulnerability?
TinyDocx runs a public bug bounty, Bug Zapper — validated, in-scope reports earn a $25 donation to the charity of your choice. To report, email security@tinydocx.com with:
  • A clear description of the issue and its impact,
  • Steps to reproduce (a proof of concept helps), and
  • Any relevant URLs, screenshots, or logs.
We aim to acknowledge reports within 5 business days and to keep you updated as we investigate. See the Bug Zapper program for scope and reward details, or our Vulnerability Disclosure Policy.
Do you carry insurance, and can I get a certificate?
TinyDocx carries Commercial General Liability, Professional Liability (E&O), and Cyber Liability coverage, all placed with Hiscox. Limits and policy periods are listed under Insurance. For a certificate of insurance — including naming your entity as certificate holder or additional insured — email security@tinydocx.com.
How can I request a security review or questionnaire response?
Email security@tinydocx.com. Pre-filled CAIQ / SIG Lite responses are available in the index above.

Bug Zapper

TinyDocx Bug Bounty Program. Find a security vulnerability in TinyDocx and we will donate $25 to the charity of your choice for each one we validate.

What we reward

$25 per vulnerability that is (a) in scope, (b) previously unreported — first reporter only, and (c) a genuine security issue with real impact, with validity determined by TinyDocx at our sole discretion. The reward is paid as a $25 donation to a registered charity of the reporter's choosing once the finding is confirmed.

In scope

tinydocx.com and its subdomains, including dme.tinydocx.com.

Out of scope
  • Any system, service, or data not operated by TinyDocx, including third-party providers and any separately operated backend systems. Do not test or access these.
  • Findings without realistic security impact: missing security headers, software-version disclosure, self-XSS, clickjacking on non-sensitive pages, and automated-scanner output without a working proof of concept.
  • Denial-of-service, volumetric or load testing, spam, social engineering, and physical attacks.
Safe harbor

Good-faith research that complies with this program is authorized. TinyDocx will not pursue legal action and will work with you to resolve the issue. Good faith means staying in scope, not accessing or modifying others' data, not degrading our services, and giving us a reasonable chance to fix the issue before public disclosure.

How to report

Email security@tinydocx.com with a description, the impact, and steps to reproduce. We aim to acknowledge reports within 5 business days.

Security questions? Email security@tinydocx.com.
To report an ethics or compliance concern, use the confidential, anonymous Whistleblower Hotline.