Security & privacy
Each agency is its own boundary. Staff APIs are scoped to the signed-in user. Families never need an account. We do not claim HIPAA, a BAA, or SOC 2 because a form uses HTTPS.
Traffic is served over TLS. When the product is connected to a hosted Postgres provider, data at rest uses that provider’s disk encryption. We will not invent extra certifications.
Leads, transcripts, knowledge, and calendars are queried with the agency id from the membership — never a client-sent tenant id. One agency cannot read another.
Owner, admin, and staff roles. Integrations, billing, and staff invites are gated. Stage changes write to the audit log.
Inquiry data stays for the life of the workspace unless you delete the lead or close the agency. Export CSV first if you need a copy. Closing the tenant removes that agency’s rows.
Ava is invoked when a family sends a message. Prompts include your approved knowledge and the current intake — not other agencies’ conversations. We do not use family transcripts to advertise. See the AI disclosure.
Hosted production databases follow the provider’s backup schedule. Preview and local copies are ephemeral. Do not treat a demo workspace as your only record of a family.
No Social Security numbers, no payment card numbers, no detailed clinical histories. Share what the coordinator needs to call back: name, contact, city, the kind of help, hours, and start. Emergencies belong on 911.
Outbound referrals are HMAC-signed. Private, localhost, and metadata URLs are rejected. You choose the destination.