Security & privacy

Families type names, numbers, and care needs. Treat that as operational data — not a badge.

Each agency is its own boundary. Staff APIs are scoped to the signed-in user. Families never need an account. We do not claim HIPAA, a BAA, or SOC 2 because a form uses HTTPS.

Encryption

Traffic is served over TLS. When the product is connected to a hosted Postgres provider, data at rest uses that provider’s disk encryption. We will not invent extra certifications.

Account isolation

Leads, transcripts, knowledge, and calendars are queried with the agency id from the membership — never a client-sent tenant id. One agency cannot read another.

Staff permissions

Owner, admin, and staff roles. Integrations, billing, and staff invites are gated. Stage changes write to the audit log.

Retention and deletion

Inquiry data stays for the life of the workspace unless you delete the lead or close the agency. Export CSV first if you need a copy. Closing the tenant removes that agency’s rows.

AI data handling

Ava is invoked when a family sends a message. Prompts include your approved knowledge and the current intake — not other agencies’ conversations. We do not use family transcripts to advertise. See the AI disclosure.

Backups

Hosted production databases follow the provider’s backup schedule. Preview and local copies are ephemeral. Do not treat a demo workspace as your only record of a family.

What families should not enter

No Social Security numbers, no payment card numbers, no detailed clinical histories. Share what the coordinator needs to call back: name, contact, city, the kind of help, hours, and start. Emergencies belong on 911.

Webhooks

Outbound referrals are HMAC-signed. Private, localhost, and metadata URLs are rejected. You choose the destination.