code/+/trust primary logo full color svg

Security

Compliance & Regulatory Standards

HIPAA, GDPR, PCI DSS and Section 508 requirements, scoped in the design phase when an engagement calls for them.

What compliance standards does Code and Trust support?

When an engagement calls for it, Code and Trust builds to the requirements of HIPAA, GDPR, PCI DSS and Section 508, scoped in the design phase. When an engagement involves PHI, we sign a Business Associate Agreement. Code and Trust follows SOC 2-aligned practices for its own systems but has not completed a formal SOC 2 audit.

What does HIPAA-compliant software require?

The HIPAA Security Rule requires, among other safeguards, a risk analysis and risk management, access controls, audit controls, integrity protections, person or entity authentication and transmission security for electronic PHI, plus Business Associate Agreements with business associates that handle it. It names no encryption algorithm. Encryption and automatic logoff are addressable: each is implemented where reasonable and appropriate, or the reason it is not is documented and an equivalent alternative is used if one is reasonable and appropriate.

HIPAA Technical Safeguards We Build To

  • –

    When an engagement involves PHI, we sign a Business Associate Agreement.

  • –

    PHI encrypted at field level where required, not just at the database level.

  • –

    Audit logging requirements, including retention against the 6 years HIPAA sets for required security documentation, are scoped in the design phase.

  • –

    No PHI in application logs, error messages, or analytics pipelines.

  • –

    Data isolation per-practice: no shared data stores between separate covered entity engagements.

  • –

    Automatic session timeout on any interface that displays PHI, with the inactivity window set in the design phase.

What does GDPR compliance look like in practice?

GDPR compliance requires lawful basis for data collection, data subject rights (access, erasure, portability), privacy notices at point of collection, DPA agreements with processors, and breach notification within 72 hours. When an engagement processes personal data covered by GDPR, data subject request workflows, consent management and retention schedule enforcement are scoped in the design phase.

GDPR Implementation Checklist

  • –

    Consent management UI: granular opt-in/opt-out with timestamped consent records.

  • –

    Data export in machine-readable format (JSON/CSV) for portability requests.

  • –

    Deletion cascade scripts: a verified right-to-erasure workflow that traverses all tables.

  • –

    Privacy notice linked at every data collection point (forms, onboarding, account creation).

  • –

    Breach notification runbook documented for the 72-hour supervisory authority deadline.

How does Code and Trust handle payment card data?

PCI DSS scope depends on how an application touches card data. When an engagement takes payments, we design to keep raw card data out of the client's systems, typically through a hosted processor. SAQ A, the shortest self-assessment, is limited to card-not-present (e-commerce or mail and telephone order) merchants that fully outsource card data handling to a PCI DSS compliant provider. A merchant that handles card data in its own systems needs a more extensive SAQ or a full assessment, and its merchant level, set by the card brands, depends on transaction volume. Where custom payment processing is required, we design to minimize that scope.

What is Section 508?

Section 508 requires US federal agencies to make the information and communication technology they develop, procure, maintain or use accessible to people with disabilities. Programs that receive federal financial assistance fall under Section 504 instead. The Revised 508 Standards incorporate WCAG 2.0 Level A and AA, which cover keyboard access, compatibility with assistive technology such as screen readers, sufficient color contrast and text alternatives for non-text content.

WCAG 2.1 AA Requirements We Build To

  • –

    Full keyboard navigation: every interactive element reachable and operable without a mouse.

  • –

    ARIA landmarks, roles, and labels on all components, validated with screen reader testing.

  • –

    Color contrast ratio ≥ 4.5:1 for normal text, ≥ 3:1 for large text (WCAG 2.1 AA).

  • –

    Text alternatives (alt text) for all non-decorative images, icons, and media.

  • –

    Focus indicators visible on all interactive elements, with no removed or invisible focus rings.

  • –

    Error messages associated programmatically with their form fields, not just visually adjacent.

Is Code and Trust SOC 2 certified?

Code and Trust follows SOC 2-aligned practices (access controls, encryption, change management, incident response, and availability monitoring) but has not completed a formal SOC 2 audit. Enterprise clients requiring formal certification can conduct their own security due diligence. We provide full documentation of our practices on request.

For more detail on our security practices, view the full Security page, including infrastructure security, incident response, and how to report a vulnerability.

Have specific compliance requirements?

Tell us your regulatory environment. We'll walk you through how we've handled it before and what we'd do differently for your stack.