Security isn't a page we bolted on — it's why several of the architectural defaults exist. Here's the posture.
Only the fields a sync needs are ever moved or stored.
Per-employer credentials, mappings, and data, fully separated.
Every change and operator action is logged and reviewable.
Client, staff, and system-owner roles scope what's visible — staff access is granted per capability.
Standard encryption on every credential and record.
Operator redaction on support threads; data kept only as needed.
Security review is part of every release, not an annual event.
Want the security detail for your compliance review? We'll walk your team through it. [email protected]