Every product, document, draft, decision, and audit entry in GearDock belongs to exactly one organization, and access is checked on the server for every request.
Organization Isolation
- Data is scoped to a single organization. Nothing is shared between organizations.
- Content cannot cite another organization's documents as evidence.
- Isolation is enforced on the server and in the database, not by hiding options in the interface.
- Import batches, exports, and audit records are organization-scoped in the same way.
Access Control
Members hold roles that determine what they can do. Reviewing, approving, releasing, and exporting are distinct capabilities, so the ability to draft content does not imply the ability to approve or publish it.
Audit History
Governed actions are recorded append-only: entries are added and never edited or deleted. Corrections appear as new events. No role can remove an audit entry.
PHI Is Out of Scope
What GearDock Does Not Claim
GearDock does not claim HIPAA compliance, SOC 2 certification, FDA clearance, or any other certification. No such certification has been earned, and stating otherwise would be false. Security questions about a specific deployment should be raised directly with the team.