Security
Last updated 21 August 2026
What follows is what the software actually does today. Where something is not yet in place it says so,
because a security page that claims more than it has is the least secure thing on a website.
In place
- One database per part of the system, each with its own credential. A leaked credential reaches
one area, not everything.
- Nothing but the front door is reachable. Every internal service refuses a call that does not
carry a signed token naming the caller, and being authenticated is not enough — each route lists
which callers it accepts.
- A session is checked against the record on every request. A revoked session stops working
immediately rather than at its next sign-in.
- An append-only, hash-chained audit trail per practice. Reads are recorded too, because in
healthcare who looked is a finding of its own. Deleting from it is refused by the database.
- Two-step verification available on every account, with a password alone refused once it is on.
- Encryption in transit everywhere, with certificates validated rather than waved through.
- The assistant receives no identifying information. A request carrying a name or a date of birth
is refused, not stripped.
- Separate doors for separate audiences. The family portal is a different process with no route to
financial data and no way to reach another family’s child.
Not yet
- HIPAA readiness is a programme, not a checkbox. Business associate agreements, formal access
reviews, a written breach procedure, retention schedules and workforce training. The architecture is
built to support all of it; it does not constitute it, and we will not say otherwise.
- No independent audit yet. No SOC 2, no penetration test by a third party. When there is one we
will publish the date and the scope.
Reporting something
If you find a weakness, write to us and we will answer. We will not take legal action against someone who
reports a problem in good faith and gives us a reasonable chance to fix it before telling others.