Skip to content

Security

Security at HomeCareIntent

What we protect, how we protect it, and what we don't claim.

Certifications

We do not currently hold third-party certifications. HomeCareIntent is not SOC 2, HIPAA or ISO 27001 certified, and we don't claim PCI certification; card payments are processed by Stripe. We don't publish uptime percentages.

Controls

How the platform is built

Accounts and sessions

  • Passwords are hashed with scrypt and never stored in readable form.
  • Session tokens are stored only as hashes. Session cookies are HttpOnly and Secure.
  • Sign-in, sign-up and password reset are rate limited, with generic error messages.

Workspace access

  • Role-based access within each workspace: Owner, Admin and Member.
  • Workspace data is isolated on the server. Plan limits are enforced on the server, not in the browser.
  • Exports are limited per plan and every export is logged.

Staff and administration

  • Staff access to administration requires two-factor authentication.
  • Administrative actions are recorded in an append-only audit log.

Transport and browser

  • Traffic is encrypted in transit with TLS, with HTTP Strict Transport Security in production.
  • Security headers block framing and content-type sniffing, and a Content Security Policy restricts what pages may load.

Payments

  • Payments are handled by Stripe. We don't store card numbers.

Data ethics

Business information only.

HomeCareIntent provides information about organizations for business-to-business sales and market analysis.

  • No patient health information.

    We don't collect, infer or store information about patients, clients or their care. Our sources are organization licensing records.

  • No patient targeting.

    There are no features to identify or market to care recipients or families. HomeCareIntent is not a care finder.

  • Not a consumer reporting agency.

    Our data may not be used for decisions about credit, insurance of individuals, employment or housing.

  • People data kept to business roles.

    Names appear only where a source lists them in a business role, such as administrator, and only in the paid product, never on public pages.

Permitted and prohibited uses are set out in our Data Terms.

Report a security issue

If you believe you have found a vulnerability, tell us through the contact form with the topic “Security”. Please don't test against other customers' data or degrade the service.

Enterprise customers can request security review support as part of their agreement.