Security at Armidus

Last updated: July 22, 2026

Security built around regional care

Armidus protects clinic, owner, and patient information through country-specific environments, layered access controls, encrypted infrastructure, and strict separation between clinics.

A separate production environment for each country

Each Armidus production country operates in a dedicated Google Cloud project with its own application services, database, and secrets. Regional patient and owner records are not synchronized or merged with other country environments.

Cloud policies restrict location-based infrastructure to the environment's configured region, helping prevent data from being placed in the wrong jurisdiction through configuration error.

Singapore

Available

Singapore clinic data is stored in Armidus's Singapore environment, hosted in Google Cloud's Singapore region. Supported Vertex AI processing of Clinic Data is also configured through a Singapore regional endpoint.

Australia

Planned, not yet available

Australian clinic data will be stored in a dedicated Australian environment hosted in an Australian cloud region.

United States

Planned, not yet available

United States clinic data will be stored in a dedicated U.S. environment hosted in a U.S. cloud region.

Access is checked at every layer

Signing in does not automatically grant access to clinic or patient information. Armidus verifies the user, application context, and requested clinic or owner relationship before protected information is returned.

Clinic separation

Clinic staff can access records only through an authenticated clinic organization. Every clinic request is scoped to the relevant clinic in the API and database query.

Owner access

Pet owners receive access only after verified identity linking or a valid claim process. An owner can see only the patient records connected to their verified regional account.

Administrative access

Internal administrative access requires membership in a separately configured Armidus administration organization.

Protected in transit and at rest

Armidus runs on Google Cloud infrastructure, where customer content is encrypted at rest and service traffic is encrypted in transit. Production application traffic passes through managed HTTPS endpoints, and production services reject direct public access outside the approved load-balancer path.

Secrets stay out of application code

Database credentials, authentication secrets, payment keys, and notification credentials are stored in Google Secret Manager rather than committed to source code. Production secrets are pinned to the environment's configured region. Vertex AI access is controlled through the relevant Google Cloud project, regional configuration, service identity, and permissions.

Armidus logging rules prohibit raw authentication tokens, claim tokens, secrets, database credentials, and complete owner or patient payloads from being written to application logs.

Medical records remain clinic-specific

A patient record belongs to the clinic that created it. Armidus does not automatically merge patient records across clinics, even when the records may refer to the same biological animal.

A pet owner may be linked to records from more than one clinic, but each clinic's medical record remains separate and access-controlled.

Payment details are handled by Stripe

Armidus uses Stripe-hosted Checkout and billing-management pages. Card numbers and security codes are entered on Stripe-hosted surfaces and do not pass through Armidus application servers.

Armidus stores only the Stripe identifiers and subscription information needed to manage clinic billing.

Designed to protect service and data availability

Production databases use automated backups, point-in-time recovery, retained transaction logs, storage growth controls, and deletion protection. Production deployments create a recovery point before database migrations.

Armidus monitors service availability, application errors, latency, database capacity, and certificate expiry so operational problems can be detected and investigated.

AI organizes information. It does not make medical decisions

Armidus uses Vertex AI to help structure information provided by the clinic. For the Singapore Service, supported models and features process Clinic Data through a Singapore regional endpoint. Armidus does not enable global endpoints, cross-region fallback, or AI features that require Clinic Data to be processed outside the configured region.

Google's applicable Cloud terms state that Google does not use Customer Data (as Google defines that term in its Cloud agreement) to train or fine-tune AI or machine-learning models without prior permission or instruction.

AI output is validated by the application and reviewed by clinic staff before being sent to an owner. Armidus does not use AI to diagnose patients, prescribe treatment, or replace veterinary clinical judgment.

Transparent about the services we rely on

Armidus uses specialized providers for cloud hosting, authentication, email delivery, payments, website operations, and business communications. Core regional application records and supported Vertex AI processing remain in the configured country region. Some other providers may process limited information in other jurisdictions.

Review our Data privacy overview, Privacy Policy, Data Processing Addendum, and Subprocessors and Service Providers page. To report a security concern, use the Security option on our request form.

Our security roadmap

Armidus is building its security program to support independent assurance as the company and customer base grow.

ISO/IEC 27001

Our roadmap includes formalizing an information security management system and preparing for independent ISO/IEC 27001 certification.

SOC 2

Our roadmap also includes readiness work for an independent SOC 2 examination covering controls relevant to security and availability.

Operational maturity

Planned work includes formalized access reviews, vendor risk management, incident-response exercises, tested recovery procedures, vulnerability-management reporting, and documented data-retention and deletion workflows.

Current status

Armidus is not currently ISO/IEC 27001 certified and has not yet completed a SOC 2 examination. We will update this page when independently verified assurance is available.