BadgeDog

Trust Center

Your IT department has a checklist. This page is where it starts — and the short version is: ask us, and we'll show you.

Documentation, on request

Our internal policies and compliance documentation — security policies, architecture overviews, data-handling procedures, and the compliance items your contract defines — are available per contract, per client. We don't post them publicly, for the same reason we don't publish a customer list. Name what your review needs, and we provide it to meet your department's requirements.

How BadgeDog is built

  • One isolated database per department. Your data never shares a database with anyone else's — isolation is the architecture, not a setting.
  • Event-sourced, with a full audit log. Nothing is edited or deleted; every action lands on a permanent ledger you can rewind and step through.
  • Role-based access control. Who can see and do what is defined by role, granted by your admins, and logged.
  • Encrypted in transit, private by default. TLS everywhere; files are served through expiring links, never public buckets.
  • Hosted in the United States, on a cloud environment that carries its own SOC 2 Type 2 audit and HIPAA compliance — the provider's credentials, and we label them as such.

Who runs the infrastructure

BadgeDog runs on a fully managed cloud environment — and that's a deliberate choice, not a shortcut. We don't patch servers, we don't manage networks, we don't babysit hardware. A provider whose entire business is running secure infrastructure — and who carries its own SOC 2 Type 2 audit to prove it — handles that layer for us, full time. We just build software. Your department gets a team focused entirely on the product, sitting on infrastructure run by people focused entirely on infrastructure.

Where we stand on certification

The same straight answer we give on the landing page: BadgeDog holds no certifications of its own today — no SOC 2 report, no StateRAMP or FedRAMP authorization. We are not afraid of any of these items — StateRAMP, FedRAMP, CJIS, SOC 2 Type 1 or 2 — and per contract, we will meet your needs. Your department's requirements go in the agreement, and based on those needs and requirements, we will meet them. That's not a maybe; it's what the contract is for.

Reporting a security concern

Found something? Tell us directly through the contact form — it reaches a person, fast. We'd rather hear about it twice than not at all.

← Back to home