Security
Reflects controls currently active
Active today
- All website and API traffic is encrypted in transit with modern TLS.
- Data is stored in managed infrastructure with encryption at rest.
- Intake submissions are validated on the server; client-side validation is treated as convenience only.
- Intake records cannot be read back through the public API. Database access rules permit submission only.
- Cross site request forgery protection is enabled for server actions.
- The public website does not request Social Security numbers, government IDs, dates of birth or credit reports.
- Secrets and API credentials are stored server side and never exposed to the browser.
In progress
- Authenticated client portal with hashed credentials and session management
- Multifactor authentication, required for all privileged staff accounts
- Role based access control with least privilege staff roles
- Private document storage with expiring access links and access logging
- Comprehensive audit logging of record and document access
- Rate limiting and brute force protection on authentication endpoints
We list only what is actually implemented. This page is updated as each control goes live.
