Security & Compliance

Security you can check — not just take on faith.

We audit other companies' AI for a living, so we hold our own security to the same rule we hold theirs to: show the evidence, claim only what's real, and disclose what we can't. Below is exactly how iDharma protects your data — and, just as plainly, what we don't claim.

Current posture at a glance
Every item below is implemented today.
  • HTTPS enforced, with HSTS
  • Two-factor required for admin access
  • Data encrypted in transit (TLS)
  • Nightly backups, copied off-site
  • Payments via Stripe — no card data stored
  • Role-based access & audit logging
In brief

iDharma is a small, focused company, and this page is written to match — no inflated claims, no badges we haven't earned. What follows is the security we actually run today, the third parties that can touch your data, and an honest statement of what we are and aren't certified for. If a control isn't listed here, assume we don't claim it.

Reviewed 2 July 2026 · iDharma LLC, Greenwood, Indiana
The controls

How your data is protected

The technical controls in place across the application today — grouped by what they defend.

Infrastructure & hosting

  • Laravel + MySQL on a hardened virtual server in the United States (Hostinger).
  • HTTPS enforced in production; HSTS sent on every secure response.
  • TLS certificates auto-renewed (Certbot).
  • Application secrets kept in the server environment, never in the codebase.

Authentication & access

  • Sign in with email + password or Google.
  • Two-factor authentication (TOTP), required for administrative access on production and staging.
  • Automatic account lockout after repeated failed logins.
  • Role-based access control separates admin, staff, and customer permissions.
  • Hardened sessions: HTTP-only, Secure, SameSite cookies that expire on inactivity.

Encryption & data

  • Everything travels over HTTPS/TLS in transit.
  • Passwords are one-way hashed with bcrypt — never stored in a recoverable form.
  • Sensitive tokens and signing keys are encrypted at the application layer.
  • The database sits on an access-controlled server, reachable only by the app.

Payments

  • Card payments are processed by Stripe, a PCI-DSS Level 1 provider.
  • Card details are entered directly with Stripe.
  • iDharma's servers never see or store full card numbers.

Logging & monitoring

  • Security audit log of authentication events (successful and failed logins).
  • Activity log of significant administrative actions.
  • Internal security-compliance snapshots (access, incidents, backups, TLS) reviewed by the team.
  • Application error monitoring via Sentry.

Backups & recovery

  • Automated nightly database backup.
  • Retained 14 days locally, plus an off-site copy to encrypted cloud storage (Microsoft 365 / OneDrive).
  • Off-site copies are protected in transit and by the provider's at-rest encryption — not additionally client-side encrypted.
Your data

Privacy & how we handle it

The short version lives here; the binding detail lives in the Privacy Policy.

What we collect

Account details, the audit inputs you choose to submit, and standard web/usage data needed to run the service — no more than the work requires.

Consent & retention

Consent is captured and recorded, and data is kept under defined retention policies rather than indefinitely. Public forms are protected by reCAPTCHA.

We don't sell or train on it

Your data isn't sold, and it isn't reused to build or train products. What you share for an audit is used for that audit. See Trust & Safety.

Who else can touch your data

Subprocessors, disclosed in full

We use a small set of trusted providers to run the service. We list every one that can process your data — including that audit content you submit is sent to Anthropic to generate a draft.

ProviderWhat it doesWhat it can touch
HostingerCloud hosting (our virtual server, US)Application data at rest on our server
StripePayment processing (PCI-DSS Level 1)Billing details; card data handled entirely by Stripe
Anthropic (Claude) Audit contentGenerates draft audit contentThe audit inputs you submit for a report
ResendTransactional email deliveryYour email address and message content
GoogleSign-in, reCAPTCHA, MapsAuth identifiers; form / bot-protection signals
MicrosoftSign-in, calendar, off-site backups (OneDrive)Auth identifiers; encrypted database backups
DocuSignE-signature for agreementsSigner name, email, and the document signed
ZoomScheduled video meetingsName, email, and meeting metadata
SentryApplication error monitoringTechnical diagnostic data from errors

This reflects our current integrations. If you need a Data Processing Agreement or a formal, versioned subprocessor list for procurement, email security@idharma.us and we'll provide one.

Compliance & standards

What we align to — and what we don't claim

An audit company shouldn't wear a seal it hasn't earned. So here's the honest split.

What we align our practices to

  • GDPR and CCPA principles for handling personal data.
  • The AI-governance frameworks our audit methodology measures against — NIST AI RMF, ISO/IEC 42001, SOC 2 criteria. We apply their principles to our own practice, but hold no certification in any of them.
  • Least-privilege access and defense-in-depth as operating principles.

What we are not (yet)

  • Not SOC 2 certified.
  • Not ISO 27001 certified.
  • Not HIPAA certified, and not a HIPAA business associate.

Why we say this out loud. We're an independent AI-audit company. Putting an unverifiable "in progress" badge on our own site would be the exact practice we flag in the companies we assess. When a certification is real, we'll show the certificate — not just the claim. Until then, this page is the evidence.

Responsible disclosure

Found a vulnerability? Tell us.

If you discover a security issue in our site, systems, or a report, tell us privately at security@idharma.us and give us reasonable time to fix it before any public disclosure. We commit to acknowledging good-faith reports promptly, keeping you updated, and engaging in good faith with researchers who follow this policy. Please avoid accessing or altering others' data, and stay within the scope of testing your own account.

A fuller vulnerability-disclosure policy is being published; until then, this section governs. Nothing here is a waiver of rights or a guarantee of legal safe harbor — it's our good-faith commitment to work with researchers who act responsibly.

Shared responsibility

Your part — and how to reach us

Your role in security

Security is shared. You can protect your account by using a strong, unique password, turning on two-factor authentication, keeping your login private, and reporting anything that looks off. Small habits close most of the real-world gaps.

Report suspicious activity

Security & compliance contact

For security questions, a Data Processing Agreement, a subprocessor list, or a procurement/security questionnaire, reach the right inbox directly and we'll respond.

Email security@idharma.us

Security that holds up to the same scrutiny we sell.

Real controls, honest limits, and full disclosure — the way a company that audits AI for a living has to run its own.

This page describes iDharma's security practices as of 2 July 2026 and is provided for transparency. It is informational only — not a warranty, guarantee, service-level commitment, or contract, and our practices evolve as the product does. For binding data-protection terms, request a Data Processing Agreement at security@idharma.us. Nothing on this page is legal advice.