Your Data Is Safe With Us
Pet care facilities trust Barklytic with sensitive information โ pet health records, medication schedules, owner contact details, and business financials. We take that trust seriously and have built security into every layer of the platform from day one.
Security by Layer
Authentication & Access Control
- โRole-based access control (RBAC) โ staff only see what they need
- โSession-based auth with secure, HTTP-only cookies
- โMulti-location isolation โ locations cannot access each other's data
- โOrg-level scoping enforced on every API call
- โInactive session timeout with automatic sign-out
Data Protection
- โAll data encrypted at rest using AES-256
- โAll data encrypted in transit via TLS 1.3
- โRow-level security (RLS) policies on all database tables
- โSensitive pet health and medication data handled with elevated access controls
- โPayment data never stored โ processed via PCI-compliant providers
Infrastructure Security
- โHosted on SOC 2 Type II compliant cloud infrastructure
- โAutomated backups with point-in-time recovery
- โGeographic redundancy for high availability
- โAutomated vulnerability scanning and dependency auditing
- โInfrastructure-as-code with version-controlled configuration
Monitoring & Incident Response
- โ24/7 automated anomaly detection and alerting
- โComprehensive audit logs for all data access and modifications
- โDefined incident response procedures with SLA targets
- โSecurity events logged and reviewed regularly
- โRate limiting and abuse prevention on all public endpoints
Application Security
- โInput validation and sanitization throughout
- โProtection against OWASP Top 10 vulnerabilities
- โCSRF protection on all state-changing operations
- โContent Security Policy (CSP) headers enforced
- โRegular code reviews with security focus
Responsible AI
- โScout AI operates only on your facility's own data
- โNo cross-tenant data sharing for AI model inference
- โAI recommendations are advisory โ humans remain in control
- โAI usage is auditable and transparent within your account
- โNo customer data used to train external models
Your Data, Your Rules
We believe facilities should have full control and visibility into how their data is handled.
You own your data
Your facility data belongs to you. We are custodians, not owners. You can export or delete your data at any time.
No data selling
We do not sell, rent, or share your data with third parties for advertising or commercial purposes.
Minimal data collection
We collect only what's necessary to operate the platform. No telemetry beyond what you explicitly enable.
Transparent sub-processors
We maintain a list of third-party services that process your data on our behalf and their security posture.
Responsible Disclosure
If you believe you've found a security vulnerability in Barklytic, we want to hear from you. Please report it to us directly โ we will acknowledge your report within 24 hours, investigate promptly, and keep you informed of our progress.
security@barklytic.io โSecurity questions or concerns?
We're happy to discuss our security posture in depth โ including providing documentation for compliance reviews or enterprise due diligence.
Contact Our Security Team