Security & Trust

Last updated: July 14, 2026

You're trusting FamilyCare Facility with records about the people your organization serves. Here is a plain-English, honest account of how we protect that data. We describe what we actually do — not aspirational claims.

Encryption in transit

All traffic to and from the platform is served over HTTPS/TLS. We also send HSTS so browsers only ever connect securely.

Encryption at rest

Your data lives in a managed PostgreSQL database (Supabase), where data on disk and automated backups are encrypted at rest.

Role-based access control

Every staff member gets a role — admin, manager, care staff, reception, viewer, auditor, and more — that determines exactly what they can see and do. Families get a scoped portal limited to their own loved one.

Tenant isolation (row-level security)

Each facility's data is fenced off in the database with PostgreSQL Row-Level Security policies, enforced by the database itself — so one organization can never read or write another's records.

Immutable audit logging

Sensitive actions are written to a tamper-evident, append-only audit trail with hash chaining, so the record of who did what — and when — cannot be quietly altered after the fact.

Automated backups

The database is backed up automatically by our managed database provider, so your records can be recovered in the event of a failure.

Access & account protection

Your data is yours

What we do NOT claim

We believe in being straight with you. FamilyCare Facility is not SOC 2 certified, is not HIPAA-certified, and we do not sign Business Associate Agreements (BAAs) as part of standard plans. Clinical/PHI features remain locked pending formal HIPAA compliance work. Your organization is responsible for determining whether its use of the platform involves Protected Health Information and for complying with the laws that apply to it. Please don't enter PHI unless a separate written agreement with us covers it. See our Terms of Service and Disclaimers for details.

Reporting a security concern

If you believe you've found a vulnerability or have a security question, please email us at smithappsupport@gmail.com. We take reports seriously and will respond as quickly as we can. Please don't publicly disclose an issue before we've had a chance to address it.

Changes to this page

As our security practices evolve, we'll update this page with a new "last updated" date. This page describes current practices and is provided for transparency; it is not a contract or a warranty.