SECURITY & COMPLIANCE
Data Security
SONUS SYSTEM is the operations and customer platform for hearing-care retail; SONUS AI is the AI fitting-assist module that runs on it.
This page sets out the concrete controls SONUS SYSTEM applies in transit, at rest, in backups, and at the key level — plus SEER SONUS's current compliance posture and incident-response practice. Specifics vary by engagement model.
Overview
SONUS SYSTEM handles sensitive data such as audiograms, questionnaires, and medical histories. Security is built into the product core by design. Below are the concrete controls a security reviewer looks for — not adjectives.
Scope
Typical data types: audiograms, questionnaires, medical history summaries, consultation records, follow-up records, store activity logs
Data classification: sensitive data (personal health information) / internal operational data / general data
Shared Responsibility
- Encryption (in transit and at rest)
- Access control and role management
- Audit logging and monitoring
- Backup and disaster recovery
- Vulnerability patching and system updates
- Account management and password security
- Role assignment and permission grants
- Revoking access when staff leave
- Device management and physical security
- Internal security SOPs and staff training
Threats We Mitigate
Note: This page outlines a standard configuration; actual deployment is tailored per contract (see each section).
Compliance & Standards
We label our compliance status honestly. Obligations we meet are marked “In compliance”; international standards still being built toward are clearly marked “Aligned, not certified” or “Planned.” We never display a certification badge we don’t hold.
Taiwan’s Personal Data Protection Act (PDPA) is our operative legal obligation and is implemented across our data-handling processes. ISO/IEC 27001, SOC 2, and ISO/IEC 27701 are target standards we are building toward — no third-party certification has yet been issued.
Personal Data Protection Act (PDPA)
In complianceOur operative legal obligation in Taiwan, implemented across data handling
- Personal data collected, processed, and used for specified purposes
- Data-subject rights to access, correct, and delete
- Application state hosted within Taiwan
- Sub-processing bound by contract and confidentiality terms
ISO/IEC 27001(ISMS)
Aligned, not certifiedBuilding controls toward the ISO/IEC 27001 ISMS framework (not yet certified; scope per contract / actual deployment)
- Risk assessment and risk management procedures
- Security policies and objective setting
- Continuous monitoring, measurement, and improvement
- Internal audit and management review processes
Note: certification timeline and scope can be discussed in the security package.
ISO/IEC 27701(PIMS)
PlannedPrivacy information management extension, planned as a follow-on to 27001 (evaluated against customer privacy-governance needs)
- Personal data processing flows and accountability
- Data subject rights request handling
HIPAA Security Rule Alignment
Aligned, not certifiedThe HIPAA Security Rule groups safeguards into three categories. Our technology and processes align with the following requirements:
Administrative Safeguards
Maps to 45 CFR 164.308
- Risk analysis and risk management
- Security awareness and training
- Security incident procedures
- Vendor management and contractual controls
Physical Safeguards
Maps to 45 CFR 164.310
- Facility access control and monitoring
- Workstation and device security
- Media disposal and destruction procedures
Technical Safeguards
Maps to 45 CFR 164.312
- Access control (unique user IDs, automatic logoff, etc.)
- Audit controls and logging
- Integrity controls (preventing improper changes)
- Transmission security (TLS encryption)
SOC 2 Type II
PlannedA service-organization controls report, on our compliance roadmap (no audit under way; no auditor or report to share yet)
Until a report exists, we can share a self-assessment of the corresponding controls — with no implication that an audit has been passed.
Security Package (Trust Center)
The following documents are confidential and provided under NDA per review needs — not offered as public downloads. Request them from us:
Note: Actual compliance scope and standards are tailored to your engagement model, deployment, and contract terms. Items marked “Aligned” or “Planned” are not yet third-party certified. Contact our customer team with any questions.
Architecture
Select a layer below to see its technology and security objectives.
In Transit
At Rest
Backup & Recovery
Backup strategy is tailored to rollout scale and contract terms; the following is a standard configuration.
| Item | Approach | Notes |
|---|---|---|
| Backup encryption | AES-256 | Backup files are stored encrypted |
| Key management | Separated via KMS | Keys are kept separate from backups to reduce single points of failure |
| Recovery process | Available on request | Recovery and data export procedures available on request |
| Backup strategy | Negotiable | Retention period and recovery targets per contract |
Key Management
Keys are centrally managed by a KMS (Key Management Service) following the process below.
Generate
Keys are generated and held by a dedicated KMS service
Rotate
Rotated on a policy schedule to limit long-term exposure
Authorize
Different roles and services get distinct authorization scopes
Audit
Key usage and authorization changes are fully traceable
Access & Audit
Data access is layered by role, following the principle of least privilege.
| Role | Visible Data | Allowed Actions |
|---|---|---|
| Headquarters | Aggregated data across all stores | Permission management, report export, system settings |
| Store Manager | Own store data and customer records | Assign tasks, store reports, customer management |
| Store Staff | Customer data assigned to them | Add records, update progress, view recommendations |
Audit Controls
Incident Response & Notification
We maintain a defined incident-response process covering detection, containment, root-cause analysis, and recovery.
Notification window: On confirming a security incident affecting customer personal data, we aim to notify affected customers within 72 hours, in line with contract terms and applicable law.
Data Subprocessors
The platform relies on a small set of cloud infrastructure and managed-service providers to process data, with application state hosted within Taiwan.
A complete list of subprocessors and their roles is available under NDA in the security package (Trust Center).
