What Protects Your Data, and What We Will Not Claim About It
This page lists the controls that actually exist and states plainly what GearDock does not have. Both halves matter. A vendor that only lists its strengths has told you very little.
Start Here
What GearDock Does Not Claim
Every one of these appears on a great many software websites. None of them is true of GearDock today, so none of them appears anywhere else on this site.
HIPAA Compliance
GearDock is not a HIPAA-compliant system and must not be used with protected health information.
SOC 2 Certification
No SOC 2 audit has been completed, and no report exists.
FDA Approval or Clearance
GearDock is catalog software. It is not a medical device and holds no regulatory clearance.
Guaranteed Accuracy
A manufacturer document can be wrong, and reading a dense table can go wrong. Being able to trace a claim lets you find and fix those errors. It does not prevent them.
Zero Risk
No software removes the risk of publishing something incorrect. GearDock lowers it and makes it correctable.
Publishing Without a Person
Human review and a separate release decision are required. That is a deliberate design choice, not a gap we intend to close later.
No Patient Information
GearDock is not a system for patient data. Do not upload or submit patient records, clinical notes, or any protected health information. That includes service reports, work orders, and maintenance records, which frequently contain patient or facility data even when the product itself does not.
The Controls
Six Things the Platform Actually Enforces
Described in enough detail to evaluate, and no more. Implementation specifics are left out because they would be more useful to an attacker than to you.
Your Data Stays Yours
Every product, document, draft, decision, and audit record belongs to exactly one organization.
Nothing is shared between organizations.
Content cannot cite another organization's documents as evidence.
The boundary is enforced on the server and in the database, not by hiding buttons in the interface.
Import batches, exports, and audit records are scoped the same way.
Roles That Are Actually Separate
Members hold roles that decide what they can do, and the powerful actions are kept apart on purpose.
Being able to write content does not let you approve it.
Being able to approve content does not let you release it.
Being able to release does not let you change organization settings.
Every request is authorized on the server, not in the browser.
A Person Approves Before Anything Leaves
Content only leaves GearDock after a person has approved it and a separate decision has released it.
GearDock does not approve its own drafts under any configuration.
Approval and release are two separate recorded decisions.
The release state is re-checked at the moment an export runs.
Shopify delivery creates drafts, never live listings.
Evidence and Version History
What a statement was based on, and what the content said at a given moment, both stay available.
Published statements stay linked to the passage that supports them.
Editing creates a new version instead of overwriting the old one.
Approved versions remain visible after later edits.
You can find every product that relied on a particular document.
An Audit History Nobody Can Edit
Governed actions are written down as events, and events are only ever added.
No role can change or delete an audit entry.
Corrections are recorded as new events, so the original stays visible.
Each entry records who acted, on what, and when.
A history that can be rewritten proves nothing, which is why this one cannot be.
One Gate on the Way Out
Content leaves through a single gate, and that gate does not take the earlier checks on trust.
Only released content is eligible to be exported.
Release is verified when the export runs, not when it was requested.
Every export records what was sent, where, by whom, and how it went.
Connector credentials are stored as protected references and are never shown again after you authorize them.
Where the Controls Sit
Your Team Does Not Configure Any of This
The controls run underneath the four actions catalog staff actually perform. That is deliberate. A governance system that everyone has to understand is a governance system people work around.
Stated at the level that belongs on a public page. Ask us for more and we will answer directly.
Every request is authorized on the server, never trusted from the browser.
Access is scoped to an organization in the database itself, not only in application code.
Connector credentials are stored as protected references and are never shown again after you authorize them.
Governed actions write audit events that no role can alter afterwards.
GearDock's internal reference and administration systems are not reachable from any customer-facing surface.
The product is in private beta, so access is granted deliberately rather than through open signup.
Questions
What Security and Compliance Reviewers Ask
Is GearDock HIPAA compliant?
No. GearDock is a product catalog system, not a system for patient data. Protected health information must not be uploaded, and we make no HIPAA claim.
Do you have a SOC 2 report?
No. No SOC 2 audit has been completed. We would rather say that plainly than imply a certification we do not hold.
Can another organization see my products or documents?
No. Every record belongs to exactly one organization, the boundary is enforced on the server and in the database, and content cannot reference another organization's evidence.
Can an administrator delete an audit record?
No. Audit history is added to and never changed. Entries cannot be edited or removed by any role, and a correction is recorded as a new event alongside the original.
What happens if a source document turns out to be wrong?
You can find every product that cited it. The correction is then applied across that known set as one recorded change, with its own review and its own audit entry, rather than by searching the catalog by hand.
Where is our data stored, and who can reach it?
Data is held in managed cloud infrastructure, scoped to your organization, and reachable only through authorized requests that are checked on the server. If you need specifics for a vendor review, ask and we will answer directly rather than through a marketing page.
Will you answer our security questionnaire?
Yes, for whatever we can answer honestly. Where the answer is no, or not yet, we will say so rather than giving you a qualified yes.
We will answer what we can answer honestly and tell you plainly where the answer is no, or not yet. That is a more useful basis for a decision than a confident document.