SEER SONUS logo, back to home

SECURITY & COMPLIANCE

Data Security

SONUS SYSTEM is the operations and customer platform for hearing-care retail; SONUS AI is the AI fitting-assist module that runs on it.

This page sets out the concrete controls SONUS SYSTEM applies in transit, at rest, in backups, and at the key level — plus SEER SONUS's current compliance posture and incident-response practice. Specifics vary by engagement model.

Overview

SONUS SYSTEM handles sensitive data such as audiograms, questionnaires, and medical histories. Security is built into the product core by design. Below are the concrete controls a security reviewer looks for — not adjectives.

In Transit
TLS 1.3
At Rest
AES-256-GCM (TDE)
Keys
KMS-managed · rotated
Data Residency
Taiwan
Compliance
PDPA
Access
Least-privilege · audit log

Scope

Typical data types: audiograms, questionnaires, medical history summaries, consultation records, follow-up records, store activity logs

Data classification: sensitive data (personal health information) / internal operational data / general data

Shared Responsibility

Our Responsibility
  • Encryption (in transit and at rest)
  • Access control and role management
  • Audit logging and monitoring
  • Backup and disaster recovery
  • Vulnerability patching and system updates
Customer Responsibility
  • Account management and password security
  • Role assignment and permission grants
  • Revoking access when staff leave
  • Device management and physical security
  • Internal security SOPs and staff training

Threats We Mitigate

Unauthorized access and brute-force attacks
Credential leaks and token theft
Accidental deletion and improper operations
Malicious scanning and injection attacks
Internal privilege abuse
Single points of failure in backups and keys

Note: This page outlines a standard configuration; actual deployment is tailored per contract (see each section).

Compliance & Standards

We label our compliance status honestly. Obligations we meet are marked “In compliance”; international standards still being built toward are clearly marked “Aligned, not certified” or “Planned.” We never display a certification badge we don’t hold.

Taiwan’s Personal Data Protection Act (PDPA) is our operative legal obligation and is implemented across our data-handling processes. ISO/IEC 27001, SOC 2, and ISO/IEC 27701 are target standards we are building toward — no third-party certification has yet been issued.

Personal Data Protection Act (PDPA)

In compliance

Our operative legal obligation in Taiwan, implemented across data handling

  • Personal data collected, processed, and used for specified purposes
  • Data-subject rights to access, correct, and delete
  • Application state hosted within Taiwan
  • Sub-processing bound by contract and confidentiality terms

ISO/IEC 27001(ISMS)

Aligned, not certified

Building controls toward the ISO/IEC 27001 ISMS framework (not yet certified; scope per contract / actual deployment)

  • Risk assessment and risk management procedures
  • Security policies and objective setting
  • Continuous monitoring, measurement, and improvement
  • Internal audit and management review processes

Note: certification timeline and scope can be discussed in the security package.

ISO/IEC 27701(PIMS)

Planned

Privacy information management extension, planned as a follow-on to 27001 (evaluated against customer privacy-governance needs)

  • Personal data processing flows and accountability
  • Data subject rights request handling

HIPAA Security Rule Alignment

Aligned, not certified

The HIPAA Security Rule groups safeguards into three categories. Our technology and processes align with the following requirements:

Administrative Safeguards

Maps to 45 CFR 164.308

  • Risk analysis and risk management
  • Security awareness and training
  • Security incident procedures
  • Vendor management and contractual controls

Physical Safeguards

Maps to 45 CFR 164.310

  • Facility access control and monitoring
  • Workstation and device security
  • Media disposal and destruction procedures

Technical Safeguards

Maps to 45 CFR 164.312

  • Access control (unique user IDs, automatic logoff, etc.)
  • Audit controls and logging
  • Integrity controls (preventing improper changes)
  • Transmission security (TLS encryption)

SOC 2 Type II

Planned

A service-organization controls report, on our compliance roadmap (no audit under way; no auditor or report to share yet)

Until a report exists, we can share a self-assessment of the corresponding controls — with no implication that an audit has been passed.

Security Package (Trust Center)

The following documents are confidential and provided under NDA per review needs — not offered as public downloads. Request them from us:

Security whitepaper and controls list
Data Processing Agreement (DPA) template
Subprocessor list
Penetration-test summary (as available)

Note: Actual compliance scope and standards are tailored to your engagement model, deployment, and contract terms. Items marked “Aligned” or “Planned” are not yet third-party certified. Contact our customer team with any questions.

Architecture

Select a layer below to see its technology and security objectives.

In Transit

TLS 1.2+ encrypted transport
Prevents data from being intercepted or tampered with in transit
API gateway authentication and rate limiting
Blocks unauthorized access and brute-force attacks
WAF (Web Application Firewall) filtering
Reduces common attack risks (SQL injection, XSS, CSRF, etc.)
Service-to-service traffic over TLS
Data stays encrypted even within internal networks

At Rest

At-rest encryption (TDE AES-256)
Data is encrypted automatically on write, reducing storage media breach risk
Private network isolation
No backend services are exposed to the public internet
Principle of least privilege
Every role gets exactly what it needs — nothing more
Traceable access activity
Key operations are logged for later review and anomaly detection

Backup & Recovery

Backup strategy is tailored to rollout scale and contract terms; the following is a standard configuration.

ItemApproachNotes
Backup encryptionAES-256Backup files are stored encrypted
Key managementSeparated via KMSKeys are kept separate from backups to reduce single points of failure
Recovery processAvailable on requestRecovery and data export procedures available on request
Backup strategyNegotiableRetention period and recovery targets per contract

Key Management

Keys are centrally managed by a KMS (Key Management Service) following the process below.

01

Generate

Keys are generated and held by a dedicated KMS service

02

Rotate

Rotated on a policy schedule to limit long-term exposure

03

Authorize

Different roles and services get distinct authorization scopes

04

Audit

Key usage and authorization changes are fully traceable

Access & Audit

Data access is layered by role, following the principle of least privilege.

RoleVisible DataAllowed Actions
HeadquartersAggregated data across all storesPermission management, report export, system settings
Store ManagerOwn store data and customer recordsAssign tasks, store reports, customer management
Store StaffCustomer data assigned to themAdd records, update progress, view recommendations

Audit Controls

Access logs: Key actions are logged for later review
Anomaly detection: Alerts can be set for unusual access and activity (per deployment plan)
Least privilege: Only the permissions needed to do the work are granted

Incident Response & Notification

We maintain a defined incident-response process covering detection, containment, root-cause analysis, and recovery.

Notification window: On confirming a security incident affecting customer personal data, we aim to notify affected customers within 72 hours, in line with contract terms and applicable law.

Data Subprocessors

The platform relies on a small set of cloud infrastructure and managed-service providers to process data, with application state hosted within Taiwan.

A complete list of subprocessors and their roles is available under NDA in the security package (Trust Center).

FAQ

FAQ
Customer trust is our most valuable asset. We protect it with concrete, auditable controls.
Our security commitment
SECURITY & COMPLIANCE

Want to know how we protect your data?

Our team will walk through every layer, matched to your engagement model and compliance requirements.