Server-side authorization
Application policy and database row-level security protect personal and organization scopes in the verified local environment.
Security begins with data minimization, professional ownership, private storage, least privilege, and truthful claims about the product's current state.
Credential Loom is designed as a professional administration product—not a clinical system.
No HIPAA compliance, accreditation, or licensing-board approval claim is made.
Architecture
The implemented data phases will add verifiable controls behind each principle.
Application policy and database row-level security protect personal and organization scopes in the verified local environment.
Evidence uses opaque keys and short-lived signed access after authorization in the verified local environment.
Membership and portfolio visibility remain separate and independently revocable.
Consent, exports, evidence access, admin actions, and integration work create audit events.
Current status
Identity, storage authorization, row-level policies, and audit infrastructure are implemented and tested locally. Hosted monitoring, malware scanning, backups, and production legal review remain gated.
Review the documented boundaries or contact Credential Loom for a precise, evidence-based answer.