Security & Compliance

Handling patient-adjacent data deserves careful controls.

This page describes the controls in place today in the application. It is not a certification, an audit report, or independent verification.

Accounts and authentication

  • Email and password sign-in with enforced password requirements
  • Optional multi-factor authentication in account security settings
  • Automatic sign-out and session revocation on request
  • Self-service password changes require your current password

Access to your data

  • Row-level access rules — records are readable only by their owner and their business
  • Team members are added explicitly, by invite, with owner/admin/employee roles
  • Business admins manage seats and audits, not other employees' training records
  • Privileged actions are re-verified server-side, never trusted from the client alone

Auditability

  • An admin action log records who did what, and when
  • Certificates carry a unique, publicly verifiable credential ID
  • Your business's audit history and evidence retain a timeline of changes

Retention and deletion

  • You can deactivate or permanently delete your account from profile settings
  • Deleting your business removes team access, audits, documents and your trust badge
  • Deleting your own account is blocked while you're the sole owner of a business, so a company can never be orphaned by accident

Shared responsibility.

Protecting your data is a joint effort between the platform, your business, and you.

HIPAA TrustGuard

Provides the application, access controls, and the guardrails described above, hosted through our infrastructure provider.

Your business

Decides who holds a seat, completes the security self-audit honestly, and keeps its trust badge information current.

You

Keep your credentials secure, enable multi-factor authentication, and use a unique password for this account.

Accessibility

We aim to keep training content and account settings usable with a keyboard and a screen reader. If something doesn't work for you, let us know and we'll fix it.

Report a vulnerability

If you believe you've found a security issue, reach out with details and steps to reproduce. Please don't share the issue publicly until we've responded.

Questions before you sign up?

Create a free account and reach us from inside the product — we'll walk you through how data is handled.

Get started

Requests to access, correct, or delete personal data can be made from your account settings, or by a signed-in business owner on your behalf. See our Privacy Policy for details.