AED platform security, stated exactly.
What is confirmed today, what is in progress and what is not published yet.
Security overview
You review software before your organisation buys it. You need the security facts in plain language. This page lists the controls that ReadyAED confirms today, the gaps, and the questions that do not have a published answer yet. ReadyAED is an AED (automated external defibrillator) readiness and compliance platform. It is software only. It sells no hardware and no consumables.
The table below lists the controls ReadyAED can confirm today. A confirmed row states the control and its status. Where a control is not confirmed, the row carries a placeholder. A placeholder marks an open question. It stays until the evidence exists.
| Control | Status today |
|---|---|
| Company SSO sign-in | Confirmed. Sign in with company SSO. |
| Work email and password sign-in | Confirmed, with forgot password and keep me signed in. |
| Site staff access | Confirmed. Site staff are invited into the account. A site custodian and a last inspector are shown, and devices are assigned to a person. |
| Audit trail | Confirmed. An audit trail records user and system events, device history and inspection history. |
| Roles and permissions | confirmed role and permission model |
| Multi-factor authentication (MFA) | confirmation of security controls (MFA, encryption) |
| Encryption, hosting, backups and independent testing | security controls evidence (encryption, hosting, backups, penetration testing) — product and legal confirmation required |
| Change protection of the audit trail | engineering and legal confirmation of immutability |
Three notes on the table. The audit trail shows the latest events in the activity feed and keeps the full log. Change protection for an entry is not confirmed, so the table carries a placeholder. ReadyAED does not name the identity provider behind the SSO button.
The platform is a web application. It loads in the browser on Android and iOS phones. There is no native app and no app-store listing. The platform sends five email templates: inspection due, overdue, device used, weekly digest and invite. It does not claim delivery rates or spam-filter behaviour. One status model with four states (Ready, Due soon, Overdue, Offline) appears across web, mobile, email and print. Each state carries an icon and a word.
Compliance status
SOC 2
SOC 2 is an independent audit report about controls at a service organisation. The audit is in progress. No report date and no auditor name are published yet. SOC 2 report date and auditor, when confirmed
HIPAA
A BAA (Business Associate Agreement) is available. BAA request process and turnaround — legal confirmation needed A BAA is the contract that lets one organisation handle protected health information for another. Ask for it during procurement. Read HIPAA & data handling for what the platform stores.
Other certifications
No other certification or compliance status is confirmed for publication. The only certification statement on this page is the SOC 2 status above.
This page is general information, not legal advice. legal-approved disclaimer text this passage needs legal sign-off
Data handling and residency
What the platform stores
ReadyAED stores the records that your team creates. Device records hold facts such as brand, model, serial number and asset ID. Inspection records hold checklist answers, notes and photos. The account also holds documents, site and location data, user names and the audit trail. The register holds serial number, location path, site, status, pads expiry, battery percentage and last inspection date. The device record holds the facts, the inspection history, the event history and the documents. Documents are uploaded and downloaded per device only.
Regions
A data-region selector offers US, UK, EU, India and APAC. The region is set per site. The selector is a product setting. ReadyAED does not claim data residency or data sovereignty in any region. confirmation of data residency options
The platform formats dates, times, numbers and currency for the reader's locale. The interface is not translated. The locale switcher changes formats only.
Subprocessors
A subprocessor is a vendor that processes data for ReadyAED. A vendor stays on the list while it processes data for the platform. The list is not published yet. subprocessor list Read the Subprocessors page.
DPA
A Data Processing Agreement (DPA) sets the terms for personal data between ReadyAED and a customer. The availability and terms are not confirmed for publication yet. DPA (Data Processing Agreement) availability and terms Read the Data processing agreement page.
Availability and status
ReadyAED does not publish an uptime figure, an SLA (service level agreement) or an availability percentage. approved uptime figure The status page carries incidents and maintenance. For current service status, read the Status page. No uptime number appears on this site until the figure is approved.
Responsible disclosure
A responsible-disclosure policy is not published yet. responsible-disclosure policy If you believe you found a vulnerability, contact our security team through the Contact page. Include the page or endpoint, the time you saw the problem and the steps to reproduce it. Do not include customer data in the report.
Accessibility statement
This website targets WCAG (Web Content Accessibility Guidelines) 2.2 Level AA. Read the Accessibility statement for the target, the known issues and how to report a problem.
Send your security questionnaire to our team.
Choose security on the contact form and tell us what you need: a control description, the DPA, the subprocessor list or a BAA. Security questionnaires differ between organisations. Send yours in its own format and list the controls you need. We answer with the confirmed facts from this page and say when a question is still open.