Compliance Posture
Both examinations were performed by Johanson Group LLP, an independent licensed CPA firm, as of June 15, 2026. Each received an unqualified opinion. A SOC 2 Type II examination is planned to follow.
Insurance
| Coverage | Carrier | Limits | Policy period |
|---|---|---|---|
| Commercial General Liability | Hiscox | $1,000,000 each occurrence $2,000,000 general aggregate |
1 May 2026 – 1 May 2027 |
| Professional Liability (E&O) | Hiscox | $1,000,000 each claim $1,000,000 aggregate |
1 May 2026 – 1 May 2027 |
| Cyber Liability | Hiscox | On the certificate of insurance | On the certificate of insurance |
Cyber Liability coverage includes breach response costs, cyber extortion, cyber crime, business interruption, data recovery, and privacy protection.
Audit Reports
A Type I report addresses the suitability of the design of controls at a point in time. It does not address operating effectiveness over a period, which is the subject of a Type II examination. The HIPAA examination does not constitute a legal determination of compliance.
What the Reports Cover
- MemoryBook
- Mermaid Sea
- Hash Browns, the MUE Dictionary, and the DMEPOS fee-schedule pricer
- Senior Tree
- This trust center, the marketing site, and the status page
The excluded products serve machine-executable encodings of published regulatory reference material. They are free of protected health information by design and process no customer application data.
Data Handling
- Document content uploaded by customers
- Account metadata (email, organization, billing)
- Usage telemetry
- Payment card data
- Protected health information (see PHI status below)
- Biometric data
- Children's data
Subprocessors
View full list →AWS is treated as a carve-out subservice organization in the SOC 2 report. Subprocessors are reviewed annually under the vendor management program, including review of their available attestation reports. Customers are notified at least 30 days before a new subprocessor begins processing their data, in accordance with the applicable Data Processing Agreement.
FAQ
Where is TinyDocx data hosted?
Can I see your SOC 2 report?
What do the audit reports cover?
How is data encrypted?
Does TinyDocx use customer data to train AI models?
Can I sign a Business Associate Agreement (BAA)?
How do I report a security vulnerability?
- A clear description of the issue and its impact,
- Steps to reproduce (a proof of concept helps), and
- Any relevant URLs, screenshots, or logs.
Do you carry insurance, and can I get a certificate?
How can I request a security review or questionnaire response?
Bug Zapper
TinyDocx Bug Bounty Program. Find a security vulnerability in TinyDocx and we will donate $25 to the charity of your choice for each one we validate.
$25 per vulnerability that is (a) in scope, (b) previously unreported — first reporter only, and (c) a genuine security issue with real impact, with validity determined by TinyDocx at our sole discretion. The reward is paid as a $25 donation to a registered charity of the reporter's choosing once the finding is confirmed.
tinydocx.com and its subdomains, including dme.tinydocx.com.
- Any system, service, or data not operated by TinyDocx, including third-party providers and any separately operated backend systems. Do not test or access these.
- Findings without realistic security impact: missing security headers, software-version disclosure, self-XSS, clickjacking on non-sensitive pages, and automated-scanner output without a working proof of concept.
- Denial-of-service, volumetric or load testing, spam, social engineering, and physical attacks.
Good-faith research that complies with this program is authorized. TinyDocx will not pursue legal action and will work with you to resolve the issue. Good faith means staying in scope, not accessing or modifying others' data, not degrading our services, and giving us a reasonable chance to fix the issue before public disclosure.
Email security@tinydocx.com with a description, the impact, and steps to reproduce. We aim to acknowledge reports within 5 business days.
Security questions? Email security@tinydocx.com.
To report an ethics or compliance concern, use the confidential, anonymous Whistleblower Hotline.