Skip to content

Security

Reflects controls currently active

Active today

  • All website and API traffic is encrypted in transit with modern TLS.
  • Data is stored in managed infrastructure with encryption at rest.
  • Intake submissions are validated on the server; client-side validation is treated as convenience only.
  • Intake records cannot be read back through the public API. Database access rules permit submission only.
  • Cross site request forgery protection is enabled for server actions.
  • The public website does not request Social Security numbers, government IDs, dates of birth or credit reports.
  • Secrets and API credentials are stored server side and never exposed to the browser.

In progress

  • Authenticated client portal with hashed credentials and session management
  • Multifactor authentication, required for all privileged staff accounts
  • Role based access control with least privilege staff roles
  • Private document storage with expiring access links and access logging
  • Comprehensive audit logging of record and document access
  • Rate limiting and brute force protection on authentication endpoints

We list only what is actually implemented. This page is updated as each control goes live.