GiggEx LoginCreate account
Security & Compliance

What we can tell you plainly, and what still needs verifying.

This page is written for whoever on your team has to sign off before GiggEx touches real hospital data — with a clear line between what's already true and what's still in progress.

Formal certifications are not yet in place. We're not going to claim HIPAA or SOC 2 certification on this page until it's actually been audited and confirmed. If that's a blocker for your evaluation, ask us directly for the current timeline.
01

Access denied by default

Every table in the database starts with row-level security enabled and zero access policies. Access is added deliberately, per reviewed need, scoped to authenticated users — never open by accident.

02

Role-based access control

What a user can see and do is tied to their role and facility — an admin at one hospital doesn't get a side door into another's data.

03

Real infrastructure, named plainly

GiggEx runs on Supabase (Postgres) for data and Netlify for hosting — established, widely-audited infrastructure providers, not a homegrown stack.

04

Credentials never leave secure storage

API keys and access tokens live only where they're supposed to — never in application code, chat logs, or anywhere they could leak into a document.

Where things stand, plainly

Status, not spin

Row-level access controlBuilt
Encrypted infrastructure (transit & at rest, via provider)Built
Formal HIPAA compliance reviewIn progress
SOC 2 auditNot started
Business Associate Agreement (BAA) processAvailable on request
Ask us directly See the platform
© GIGGEX