Security and compliance
Built for health data.
This app holds children's therapy records. This is how they are protected.
At rest
Every record sealed individually
Every record is encrypted on its own before it reaches the disk, using FIPS 140-3 — the US government standard for cryptographic security. The database file on disk is ciphertext. Copying the file alone does not yield health data.
Keys
Separated from the data
The key that opens your records is kept apart from the records themselves. Holding one is separate from holding the other.
Access
Only the people you chose
Reaching a child's record takes permission from their guardian. A practitioner sees the families who connected to them. A guardian sees their own child.
Audit
Every access is logged
Each time a record is opened it is written to an append-only log that preserves history for review.
Video
Encrypted, on our machines
Exercise video is encrypted and served from our own machines. Playback stays on the service path families use — our origin, with entitlement checks.
Sign-in
Code or passkey
A six-digit code to your address, or a passkey on your device. We store session handles and credentials designed for that flow — passwords are outside the design.
Your family's personal and health records live on the node for your part of the world. Exercise videos are shared for delivery; family records stay put.
There are four nodes: Miami for the United States, Warsaw for Europe, Sydney for Australia and New Zealand, and Jakarta for South-East Asia.
A European family's records stay in Europe, under GDPR. An American family's stay in the United States. Each node meets the HIPAA standard before family records run on it.