Federal requirement — Section 155715+ employees May 11, 2027under 15 May 10, 2028nearly every provider covered
Talk to us

Security

What CivicBinder Health stores, who else processes it, and how to report a vulnerability.

Reporting a vulnerability

Email hello@thecompound.tech. Include the URL, what you did, and what you saw. There is no bounty and no NDA to sign. We will confirm receipt, and we will tell you what we changed.

The same address, with a machine-readable expiry, is published at /.well-known/security.txt under RFC 9116.

Accounts

CivicBinder Health has no user accounts. There is nothing to sign in to, no password to reset and no session to steal, and a build gate fails the deploy if an authentication route ever appears in this repository while this page still says otherwise.

What is stored

  • If you request a free scan, the organisation name, the site address and the contact details you enter are emailed to us so that somebody can answer you
  • Anonymous usage analytics — page views and clicks. Form inputs are masked in session recordings and no profile is created for a visitor who never identifies themselves

Who else processes data

  • Google Workspace — delivers the scan request to our own mailbox over SMTP
  • PostHog — anonymous product analytics, sent from your browser straight to PostHog
  • Vercel — serves this site and holds its access logs

Also true

  • No patient information ever reaches this site. Nothing here is a covered entity's system of record, nothing here touches PHI, and the accessibility work is done against your site and your documents rather than against anybody's chart.
  • There is nothing to sign in to. A request is an email to us, not an account.
  • No card number is typed on this site, and no card details reach it. The three buy buttons in the pricing band are Stripe Payment Links, and each opens Stripe's own hosted checkout on a Stripe domain.

CivicBinder Health is built and run by Compound Labs. The declarations on this page are part of this product's own configuration and are re-checked at every deploy against the repository they describe: a product that claims to have no accounts and ships an authentication route fails the build, and so does one that takes payment without naming its payment processor here.