Security at PredictiCare

Home care runs on trust. This page describes, plainly, how the platform protects the information agencies put in it.

Encryption

All traffic to and from the platform is encrypted in transit with TLS. Data is encrypted at rest by our cloud provider, and identifying client and caregiver fields carry an additional layer of application-level field encryption on top of that.

Tokenized records

Client records are referenced by opaque tokens rather than identity. What a user can resolve from a token is governed by their role and scope.

Role-based access

Every role, from super admin to family member, is scoped by permission, office, and agency. Users see exactly their scope and nothing more, enforced server-side on every request.

Session controls

Sessions end after a short idle period and carry a hard maximum lifetime. Locking an account revokes its active sessions. Multi-factor authentication (TOTP and SMS) is built into the platform and staged for activation.

Hosting

PredictiCare runs on Google Cloud in the United States, on managed infrastructure with automated patching, private database networking, and monitored budgets and logs.

Auditability

Administrative and clinical activity is captured in an audit trail so agencies can answer who did what, and when.

Business Associate Agreements are available for customer agencies. We follow applicable breach-notification law. To report a suspected vulnerability or ask a security question, write to hello@predicticare.health.