Skip to main content

Security, stated honestly

Attestly collects no client-identifying data by design. Here's exactly what we do to protect the data we do hold, and what we don't yet claim.

Our Compliance Posture

What we actually do, not what sounds impressive.

No PHI, by design

Attestly is not an EHR. There are no free-text fields, no client names, no diagnoses — only categories and quantities of time. That means no protected health information, and no HIPAA or BAA requirement.

CCPA/CPRA-aware

We still handle sensitive professional data about identifiable people — associates, supervisors, and the hours they log. California privacy law obligations apply, and we treat them as a floor, not a ceiling.

MFA required for supervisors

Every supervisor account requires multi-factor authentication, because a supervisor's signature attests hours under penalty of perjury.

Annual penetration test planned

We plan an annual third-party penetration test before any enterprise-scale sales push. We are early-stage and do not claim SOC 2 or ISO 27001 certification — claiming either now would be dishonest.

Security Features

Built-in security at every layer of the product.

Encryption at Rest & in Transit

All data is encrypted at rest and in transit using industry-standard protocols. Your logged hours and attestations are protected at every step.

MFA for Supervisor Accounts

Multi-factor authentication is required for every supervisor account, since a supervisor signature is a legal attestation made under penalty of perjury.

Least-Privilege Access

Practice administrators see compliance signals — unsigned weeks, expiring registrations, supervisee counts — never hour-level detail without an associate's explicit consent.

Audit Logging

Every access to an associate's record is logged: who viewed it, when, and under what grant. Associates can see this history for their own record.

Tamper-Evident Attestation

Every supervisor signature is hash-chained to the exact weekly record it covered. A correction after signing becomes a visible amendment, never a silent edit.

No Client Data, Ever

No free-text fields exist anywhere a client could be named. Attestly tracks categories and quantities of supervised time only — nothing else.

Data Portability

Associates can export their full record at any time, in a format readable without any Attestly software — a real disaster-recovery plan for your licensure evidence.

Automatic Backups

Regular automated backups protect against data loss. An associate's record is never dependent on a single point of failure.

No client data, ever

Attestly is not an EHR. There are no free-text fields anywhere a client could be named, and no diagnosis or clinical-note fields exist in the product at all. We track categories and quantities of supervised time — nothing more.

Because we don't collect protected health information, Attestly doesn't carry a HIPAA Business Associate Agreement burden the way an EHR would. We still handle sensitive professional data about identifiable associates and supervisors, so CCPA and CPRA obligations apply, and we design for them from day one.

We are an early-stage company. We plan to complete an annual third-party penetration test before any push into larger enterprise sales, and we will not claim SOC 2 or ISO 27001 certification until we've actually earned it.

Security Contacts

Report a vulnerability or rule inaccuracy

support@attestly.com

Privacy questions

privacy@attestly.com

General inquiries

hello@attestly.com

Security FAQ

Common questions about how we handle data.

Do you collect client data?
No. Attestly is not an EHR and never will be. There are no free-text fields anywhere a client could be identified — only categories and quantities of supervised time.
Are you HIPAA compliant?
We don't collect protected health information by design, so HIPAA's Business Associate Agreement requirement doesn't apply to Attestly the way it would to an EHR. We still take the sensitivity of professional licensure data seriously.
How do you handle data encryption?
All data is encrypted at rest and in transit using industry-standard protocols. Encryption keys are managed through a dedicated key management service.
Is my data CCPA compliant?
We are aware of and design for California Consumer Privacy Act / California Privacy Rights Act obligations, since we process sensitive professional data about identifiable people even without PHI.
Are you SOC 2 or ISO 27001 certified?
Not yet. We are an early-stage company and won't claim certifications we haven't earned. We plan an annual third-party penetration test before pursuing enterprise-scale sales, and we'll update this page honestly as our compliance posture matures.
Why does MFA apply only to supervisors?
Supervisor accounts sign weekly logs under penalty of perjury, which is why MFA is required there today. We continue to evaluate MFA for other account types as the product matures.

Need more information?

We're happy to walk through our data handling in detail — especially if you're evaluating Attestly for a practice.