Back to home

Trust & compliance

Security at CAHIR Solutions

MedTechCompass is protected by layered controls across infrastructure, application access, and payments — designed for organizations whose regulatory strategy is confidential.

Platform compliance

Certified cloud infrastructure. MedTechCompass is hosted on cloud infrastructure that maintains SOC 2 Type II and ISO 27001:2022 certifications, with independent audits of the underlying hosting environment's security, availability, and confidentiality controls.

These certifications apply to the hosting infrastructure. CAHIR Solutions builds additional application-level controls on top, described below.

Application security controls

Row Level Security everywhere

Every database table enforces Row Level Security. Security-definer functions are locked down — no anonymous or broad authenticated EXECUTE access.

Approval-gated access

Sign-ups land in a pending state. An administrator reviews and activates (or rejects) every workspace before any data is visible.

Tier-based entitlements, server-side

Feature access is enforced on the server. Roles are checked via a security-definer function and are never stored on user profile records.

Encryption in transit and at rest

Data is encrypted in transit (TLS) and at rest (AES-256) through the managed database layer.

PCI-DSS payments via Stripe

Payments are processed by Stripe, a PCI-DSS Level 1 service provider. Card and bank data never touch CAHIR servers.

Anonymous access revoked

Sensitive caches and billing tables are scoped by RLS to organization members and admins only. Anonymous access is revoked from regulatory caches.

Data handling

  • Organization isolation. Subscriber data is isolated per organization (scoped by client identifier), enforced by database policies rather than application convention alone.
  • No sale of data. CAHIR Solutions does not sell, rent, or trade subscriber data or uploaded content.
  • Controlled evidence uploads. Documents uploaded to the evidence console are stored in access-controlled storage, reachable only by authorized members of the owning organization.

Responsible disclosure

If you believe you have found a security vulnerability in MedTechCompass, we want to hear from you. Please report it to our security team at security@cahir.ai. We investigate every report and will respond as quickly as possible. Please do not publicly disclose the issue until we have had a reasonable opportunity to address it.

This page describes the security controls currently implemented for MedTechCompass as operated by CAHIR Solutions (Cahir AI LLC). It is informational and does not itself constitute a certification, audit report, or guarantee against all possible threats. Controls evolve over time and this page will be updated as they do.