Skip to content
Security

Protect the record. Limit the access. Preserve the truth.

Security begins with data minimization, professional ownership, private storage, least privilege, and truthful claims about the product's current state.

Security posture

Credential Loom is designed as a professional administration product—not a clinical system.

No HIPAA compliance, accreditation, or licensing-board approval claim is made.

Architecture

Defense in depth from request to storage.

The implemented data phases will add verifiable controls behind each principle.

Server-side authorization

Application policy and database row-level security protect personal and organization scopes in the verified local environment.

Private object storage

Evidence uses opaque keys and short-lived signed access after authorization in the verified local environment.

Granular consent

Membership and portfolio visibility remain separate and independently revocable.

Audit events

Consent, exports, evidence access, admin actions, and integration work create audit events.

Prohibited contentDo not submit patient records, diagnoses, treatment details, clinical notes, or other clinical information to Credential Loom.

Current status

Security claims follow implemented evidence.

Identity, storage authorization, row-level policies, and audit infrastructure are implemented and tested locally. Hosted monitoring, malware scanning, backups, and production legal review remain gated.

  • Security headers and strict TypeScript foundation are implemented.
  • Supabase RLS and private storage are implemented and verified locally, but no hosted project is approved.
  • Automatic provider integrations and external AI extraction are disabled.
  • Production legal, privacy, retention, backup, and incident-response review remains required.

Have a security question?

Review the documented boundaries or contact Credential Loom for a precise, evidence-based answer.