Skip to content
GearDock

Documentation

Security and Tenancy

How organizations are isolated, how access is controlled, and what GearDock does not claim.

Last updated

Every product, document, draft, decision, and audit entry in GearDock belongs to exactly one organization, and access is checked on the server for every request.

Organization Isolation

  • Data is scoped to a single organization. Nothing is shared between organizations.
  • Content cannot cite another organization's documents as evidence.
  • Isolation is enforced on the server and in the database, not by hiding options in the interface.
  • Import batches, exports, and audit records are organization-scoped in the same way.

Access Control

Members hold roles that determine what they can do. Reviewing, approving, releasing, and exporting are distinct capabilities, so the ability to draft content does not imply the ability to approve or publish it.

Audit History

Governed actions are recorded append-only: entries are added and never edited or deleted. Corrections appear as new events. No role can remove an audit entry.

PHI Is Out of Scope

GearDock is a product catalog system. Do not upload or submit patient records, clinical notes, EMR content, or service documents containing patient data.

What GearDock Does Not Claim

GearDock does not claim HIPAA compliance, SOC 2 certification, FDA clearance, or any other certification. No such certification has been earned, and stating otherwise would be false. Security questions about a specific deployment should be raised directly with the team.

Something here unclear or out of date? Tell us Documentation gaps are worth more to us than feature requests.