Security
What runs on this computer today, and what is not built yet.
Running today
What is running
Where the book lives
Right now your records are saved on this device only. Export regularly. Clearing the browser's data or losing the computer loses the book.
Download PDF or JSON from this computer.
Tamper evidence
Each drug line is hashed with SHA-256, and the hash includes the previous line. This proves entries weren't changed in place since they were written on this device. It can't prove the book wasn't rebuilt by someone with full control of the device. Your exported PDFs are your independent record.
Support access
Support cannot open this book. There is no copy on a server. Support cannot insert, update, or delete a drug line.
State rules
Which states have prompts built in is on the Compliance page.
Who can write
Staff sign a dose with a 6-digit PIN on this computer. The PIN is stored as PBKDF2-SHA-256 with 310,000 iterations and a salt that belongs to that person. The older short hash is retired. Five wrong tries lock that person for 5 minutes on this book, and the wait grows. After 10 misses, the owner resets the PIN. Every lock and reset is an audit line. Fingerprint and passkey are not used for signing doses. Staff PINs are a sign-in for one clinic computer, not a password for an account.
One sign-in per vet
DEA records must show who gave each dose; a shared PIN makes your log wrong.
- One sign-in per license number inside this clinic. A second sign-in with the same license number is refused.
- A technician signs under their own name. That line is never recorded under a veterinarian's name. Where a veterinarian co-sign is required, it has to be a different veterinarian's PIN.
- Same-device notes only: one veterinarian PIN with two open sign-ins on this computer, and a high dose count for one veterinarian on this computer. The owner reviews them. They do not change the bill, and they do not stop a dose or an export.
- Passkey is a preview. It is not a sign-in on this computer, and nothing requires it. Your fingerprint or face never leaves your device. Holdra never sees it.
Not built yet
What is not built
Sign-in
- Server-side lockout.
- Enrolled-device owner sign-in: email, password, and a second factor, with a revocable device token.
- Server-checked passkeys, and re-binds confirmed from the vet's own email.
Licenses
- One sign-in per license across clinics.
- Cross-device flags.
- Yearly license re-check.
Outside checks
- No SOC 2 report or independent security audit. There is no badge on this site.
- No third-party penetration test.
- No cyber insurance.