Security, stated honestly
Attestly collects no client-identifying data by design. Here's exactly what we do to protect the data we do hold, and what we don't yet claim.
Our Compliance Posture
What we actually do, not what sounds impressive.
No PHI, by design
Attestly is not an EHR. There are no free-text fields, no client names, no diagnoses — only categories and quantities of time. That means no protected health information, and no HIPAA or BAA requirement.
CCPA/CPRA-aware
We still handle sensitive professional data about identifiable people — associates, supervisors, and the hours they log. California privacy law obligations apply, and we treat them as a floor, not a ceiling.
MFA required for supervisors
Every supervisor account requires multi-factor authentication, because a supervisor's signature attests hours under penalty of perjury.
Annual penetration test planned
We plan an annual third-party penetration test before any enterprise-scale sales push. We are early-stage and do not claim SOC 2 or ISO 27001 certification — claiming either now would be dishonest.
Security Features
Built-in security at every layer of the product.
Encryption at Rest & in Transit
All data is encrypted at rest and in transit using industry-standard protocols. Your logged hours and attestations are protected at every step.
MFA for Supervisor Accounts
Multi-factor authentication is required for every supervisor account, since a supervisor signature is a legal attestation made under penalty of perjury.
Least-Privilege Access
Practice administrators see compliance signals — unsigned weeks, expiring registrations, supervisee counts — never hour-level detail without an associate's explicit consent.
Audit Logging
Every access to an associate's record is logged: who viewed it, when, and under what grant. Associates can see this history for their own record.
Tamper-Evident Attestation
Every supervisor signature is hash-chained to the exact weekly record it covered. A correction after signing becomes a visible amendment, never a silent edit.
No Client Data, Ever
No free-text fields exist anywhere a client could be named. Attestly tracks categories and quantities of supervised time only — nothing else.
Data Portability
Associates can export their full record at any time, in a format readable without any Attestly software — a real disaster-recovery plan for your licensure evidence.
Automatic Backups
Regular automated backups protect against data loss. An associate's record is never dependent on a single point of failure.
No client data, ever
Attestly is not an EHR. There are no free-text fields anywhere a client could be named, and no diagnosis or clinical-note fields exist in the product at all. We track categories and quantities of supervised time — nothing more.
Because we don't collect protected health information, Attestly doesn't carry a HIPAA Business Associate Agreement burden the way an EHR would. We still handle sensitive professional data about identifiable associates and supervisors, so CCPA and CPRA obligations apply, and we design for them from day one.
We are an early-stage company. We plan to complete an annual third-party penetration test before any push into larger enterprise sales, and we will not claim SOC 2 or ISO 27001 certification until we've actually earned it.
Security Contacts
Report a vulnerability or rule inaccuracy
support@attestly.comPrivacy questions
privacy@attestly.comGeneral inquiries
hello@attestly.comSecurity FAQ
Common questions about how we handle data.
Do you collect client data?
Are you HIPAA compliant?
How do you handle data encryption?
Is my data CCPA compliant?
Are you SOC 2 or ISO 27001 certified?
Why does MFA apply only to supervisors?
Need more information?
We're happy to walk through our data handling in detail — especially if you're evaluating Attestly for a practice.