Security and procurement

What a security reviewer would find, including what is missing.

Most security pages are written to end a conversation. This one is written to start one accurately: the access model and record-handling we can describe, the subprocessors we have verified, and the things a larger buyer expects that HempDash does not have yet.

Security record reviewed August 17, 2026

Read this first

What HempDash does not have

These are the questions an enterprise security review asks first. Each answer below is no. They are listed here rather than left for a questionnaire, because finding them later is worse than reading them now.

No security certification
There is no SOC 2, ISO 27001, or equivalent third-party attestation, and therefore no audit report to share. Nothing on this site should be read as implying one.
No single sign-on
There is no SAML, no OIDC federation with your identity provider, and no SCIM provisioning. Accounts are created and removed in HempDash.
No published penetration test
No third-party penetration test result is published. If an engagement is a precondition for you, that is a scoping conversation, not a form.
No availability commitment
A live service-status page for the vendor platform is published at store.gethempdash.com/status; it reports current health and response time, refreshed every thirty seconds. It carries no incident history, no uptime percentage, and no availability target, so nothing here should be read as one being measured or promised.
No POS integration
HempDash does not integrate with Cova, Dutchie, Shopify, or any other point-of-sale system. It runs alongside whatever you already use.

Enforcement

What the platform enforces

Each statement below renders only while the evidence behind it is current. Where you see a narrower sentence than you expected, that is the gate working, not the capability being coy.

How a statement earns its place here is set out in the Trust Center.

AccessRoles are fixed, and defined in one place
Team access is governed by defined roles rather than per-user permission toggles. The specifics render here once the current evidence for them is on record.
TenancyOne organization cannot read another's records
Each organization's records are scoped to that organization. The specific enforcement statement renders here once it has been observed in production rather than only in source.
RecordsNothing deletes compliance evidence
Compliance evidence is kept, not rotated away. The retention schedule renders here once the current evidence for it is on record.

Public record

Subprocessors for this website

These are the providers that process data from gethempdash.com on our behalf. Each is bound to use it only to provide their service to us. This list covers the public website; it is not the platform list.

Subprocessors for this website
ProviderWhat it processes
NetlifyHosting and content delivery, and the store that holds first-party site usage events. Processes IP addresses as an inherent part of serving requests.
RailwayHosts the scheduling system used to book a working session, and the internal messaging system that receives signups and applications.
SanityContent management for Academy and article pages. Some lesson media is delivered from Sanity's network directly to the browser.
OpenRouterPrimary AI provider for the free COA check. Receives text extracted from an uploaded document, solely to locate the fields the check reads.
AnthropicFallback AI provider for the free COA check, for the same field-location purpose when the primary is unavailable.
GoogleGoogle Analytics receives a server-sent mirror of part of the first-party usage measurement. No tag runs in the browser and no cookie or persistent identifier is involved.

The platform subprocessor list is not published here

The vendor platform uses a different and larger set of providers than this website. That list is not published yet, because it has not been verified to the standard this page holds itself to, and a plausible-looking list is worse than none. It is available to customers and to prospects in procurement on request.

How records are handled

The free COA check keeps nothing

A document uploaded to the public check is processed in memory and is not written to a database, to file storage, or to temporary files. Extracted text goes to an AI provider solely to locate fields. Logs carry the request size and outcome, never document content.

Site measurement is first-party

Usage events are recorded to our own store, which is the system of record. The Site sets no cookies and runs no analytics script in your browser. What is mirrored to Google Analytics, and how, is set out in the Privacy Policy.

Evidence is append-only by intent

Compliance events are written as records rather than edited in place, so the history of a decision survives the decision changing. This is a design property of the record store, not a certification.

The full data terms are in the Privacy Policy and Cookie Policy.

Procurement

Working through procurement

If you are running a vendor review, these are the routes that exist today. Where something does not exist, the answer above says so rather than routing you into a queue.

Security questionnaires
Send it. Answers come back referencing this page and the Trust Center, and any answer that would overstate what exists is returned as a no rather than a qualified yes.
Data processing agreement
A DPA is available on request as part of contracting.
Reporting a vulnerability
Email the founder directly. There is no bug-bounty programme and no triage queue; reports reach a person.
Claims that look wrong
If a statement on this site does not match what you find in the product, that is a defect worth reporting on the same address, and it will be corrected or withdrawn.

Ask the awkward question first

Security review is cheaper before a pilot than after one. If something here rules HempDash out for you, that is a useful outcome and worth five minutes.

Email the founder