Security & Compliance
Last updated August 2026
Tenant isolation
Every resident, staff, scheduling and billing record carries a facility identifier, and access rules are enforced in the database rather than in the interface. A request for a record outside the signed-in user's facility returns nothing, regardless of how it is made.
Role-based access
Facility administrators define roles with granular permissions — viewing clients, writing case notes, managing schedules, handling billing, running reports. Navigation, pages and actions are all gated by those permissions, and privileged fields such as role membership cannot be self-assigned.
Data protection
- Traffic is encrypted in transit; data is encrypted at rest by the hosting platform.
- Uploaded documents are held in a private store reachable only via short-lived links.
- Passwords are hashed and checked against known breach corpora at sign-up.
- Sessions can be revoked across all devices from account settings.
Auditability
Published case notes are immutable: corrections are recorded as addenda rather than edits, and status changes for residents are written to a permanent history. Deactivating a user preserves everything they authored.
Responsible disclosure
If you believe you have found a vulnerability, email andrew@leanengineering.io with the details and steps to reproduce. Please do not access data that is not yours while testing. We will acknowledge reports and keep you updated until the issue is resolved.