Security & Compliance

    At NarcTrack, security is not an afterthought—it's the foundation of everything we build. We understand the critical nature of medication tracking and the sensitivity of the data involved. Here is how we protect your agency's data.

    Infrastructure Security

    NarcTrack is built on Supabase, an enterprise-grade backend-as-a-service platform. Supabase operates on AWS data centers that are SOC 1, SOC 2, and ISO 27001 certified — certifications NarcTrack inherits at the infrastructure layer. Supabase's compliance attestations are publicly available at supabase.com/security.

    Data Encryption

    Your data is protected at every stage. We employ AES-256 encryption for data at rest and TLS 1.2+ for data in transit. This ensures that sensitive information, including inventory logs and user actions, remains unreadable to unauthorized parties.

    Access Control

    We implement strict Role-Based Access Control (RBAC) at the database level. Row Level Security ensures users can only access data they are explicitly authorized to see. Multi-Factor Authentication (MFA) is required for all administrative and supervisor-level accounts.

    HIPAA & SOC 2

    Our platform is designed for HIPAA compliance. Supabase is SOC 2 Type 2 compliant and HIPAA compliant, and NarcTrack has an executed Business Associate Agreement (BAA) with Supabase covering our infrastructure layer. A BAA is included as a standard exhibit in every NarcTrack Platform Agreement with a covered entity — no tier or size requirement.

    Vulnerability Disclosure

    We take security reports seriously. If you believe you have found a security vulnerability in NarcTrack, please contact us immediately at security@narctrack.io. We will investigate all reports and work with you to resolve valid issues promptly.