BookNovi keeps every business's records apart, logs every change and every look at a client's record, seals what must be sealed and keeps a copy of everything every night. Admin, Compliance is where a business sees its own side of that against SOC 2, ISO 27001 and HIPAA, switches on what its kind of business needs, and keeps the evidence an auditor asks for. It is for an owner, or an admin with the business settings switch; the policy, the health-information switch, retention, the legal hold, closing an incident and signing the access review off are an owner's alone.
Overview
The controls list each thing the three frameworks ask for, with the SOC 2 criterion, the ISO 27001 control and the HIPAA section it answers, what BookNovi does for it, and where it stands for your business: In place, Partly or To do, read from your records. The controls come in four kinds: what the platform does for every business, a switch you set here, a written policy (the pack is in the repository under docs/policies), and what the platform's owner buys or signs (an auditor, the business associate agreements, a penetration test, insurance). Filter by kind across the top.
Keys and Sign-Ins, Sealed counts every key, sign-in, bank detail and webhook secret your business keeps, and with health information on, its sealed notes and forms: how many are on the current key, how many are waiting for the clock, and how many no key opens. Each is sealed under the server's own secret, carries the id of the key it was sealed with, and is bound to the record it belongs to, so it opens there and nowhere else. When BookNovi changes that secret, the app's clock moves every value to the new one a batch at a time each day, and everything opens as before meanwhile. A value no key opens is listed by what it is (a mailbox's sign-in, a carrier account's credentials): connect that app or account again where it is set up. On a server whose secret is not set, nothing new can be kept, and connecting an app or saving a key stops with a sentence that says so.
The Evidence says what the records hold for the last ninety days and opens each place in full: the team and their switches, the activity log with its sign-ins and exports, the access log, the last review, the incidents, the night's copies, how much health text is sealed, and the keys and webhooks.
Sign-in
The Session Policy has three parts. Sign an idle login out after so many minutes with nothing touched: the app warns for a minute, then signs the login out and notes it in the activity log. A sign-in holds for so many hours at most, after which the person signs in again. A second factor is required of nobody, owners and admins, or everyone. Use the HIPAA setting fills in 15 minutes, 12 hours and owners and admins, which is what the Security Rule's automatic logoff asks for in practice. A person in more than one business is held to the strictest of their businesses' policies.
A login that must have a second factor is sent to set it up at its next sign-in: scan the code with any authenticator app (Google Authenticator, Microsoft Authenticator, 1Password, Authy), type the six-digit code the app shows, and keep the eight recovery codes, each of which signs you in once if you lose your phone. The code's secret never leaves the server except in that scan. Anyone can set up or remove their own from Your sign-in in their menu, whatever the business asks; removing it takes a code.
Sign-Ins in the Last 30 Days lists each sign-in, each password that did not match and each sign-out, with who and from where. The same rows are in the activity log, one for each business the person belongs to.
Phones Signed In lists the phones signed in for the team, each to sign out when it is lost. Under it, Tags the Phones Write says whether an NFC tag the phone app writes (for a stock place or a bin, a room, chair or table, or a customer's door) is locked once it is written: Lock each tag once it is written keeps what a tag says for good, so nobody can write over it, and it can never be unlocked; left off, tags stay open to be written again. It holds for tags written from then on.
Health information
A clinic, a med spa, or anyone keeping treatment notes and intake forms handles protected health information. Switched on, a client's notes, formulas and treatment notes and what clients answer on forms are sealed in the database under a key of their own, so a copy of the database alone gives up none of it; what was written before the switch went on is sealed in the background from the moment it is switched on, two hundred at a time until none is left, on its own so it never waits behind another business, and the tab says how many are still in the clear. A reminder to a client says "your visit" and never the service, since a text can be read by someone else and a service's name can say what a person is being treated for. A webhook carries no client's notes and no answers on a form, only that the form was filled; Klaviyo and Mailchimp are not told what a client booked or bought. Forms and notes are kept at least six years, and an idle sign-out within the hour is required.
The screens, the PDFs and your downloads read sealed text as before; the assistant does not read it. Switched off again, what is sealed stays sealed and still opens; new text is kept in the clear.
Access review
Every login, its place on the team and what it can do, when it last signed in, whether it has a second factor, and how many sign-ins, exports and looks at clients' records it made in the last ninety days. Read it, take away what nobody needs any more under Settings, Team, and Sign the review off with what was found; the list as it stood is kept with your name and the day, and the Overview says when the next one is due. A review is due each quarter.
Incidents
Log an incident the moment something is found: a lost tablet, a form sent to the wrong person, an outage, a vulnerability, a suspected or confirmed breach, with how bad it is and when it was discovered. An open incident holds the business's records from the retention purge until it is closed, unless you say otherwise. Keep notes on it as it is worked: what was found, who was called, what was done.
With health information involved, the people affected are told without unreasonable delay and within sixty days of discovery; the day a notice is due is set from the discovery and shown on the incident, and the incident cannot be closed until the day they were told is recorded. Close the incident with what caused it and what was done; it can be opened again if more comes to light. The runbook, who does what in the first hour, the first day and the first week, is in docs/COMPLIANCE.md in the repository.
Retention
How long texts and emails, filled forms, notes and formulas, and the event stream are kept: forever, or from ninety days to ten years. Past the days set, records are let go in the background, a thousand at a time until none is left: as soon as the days are set or shortened (or a hold is lifted), and every day after. The tab says what the next pass would let go and what the last one did. With health information on, filled forms and notes are kept at least six years. The activity and access logs are never purged: they cannot be changed or removed by anyone, and are kept at least six years.
Legal Hold stops every purge until it is lifted, whatever the days say: put one on when a lawyer, an insurer or an investigation asks that nothing be let go, with why, so whoever lifts it knows.
Best practices
- Switch on health information before the first treatment note is written, so every note is sealed as it is written.
- Require a second factor of owners and admins at least: they are the logins that can change settings, logins and the books.
- Sign the access review off each quarter, and the day someone leaves the team: pause their login under Settings, Team, turn their keys off, and note it in the review.
- Log an incident even when it turns out to be nothing; a closed incident with "nothing was taken" is better evidence than silence.
- The agreements with the services the platform runs on, the penetration test and the insurance are the platform's owner's; the Overview says which are still to do.