Trust
Public Website Security Policy
This policy describes the safeguards and security practices verified for the CareBridge public website and explains their limits.
Effective date: July 24, 2026
1. Scope
This policy covers the public CareBridge website, its forms, newsletter feature, assistant, and the server routes that support them. Customer environments, clinical data, implementation controls, and contractual security obligations must be evaluated separately.
2. Verified technical controls
The published application configures a Content Security Policy, same-origin framing restriction, MIME-sniffing protection, a restrictive permissions policy for camera, microphone, and geolocation, and a strict-origin referrer policy.
These controls reduce specific browser and application-delivery risks; they are not a certification, audit result, guarantee, or statement of compliance with a particular security framework.
3. Data minimization
Do not submit protected health information or identifiable patient information through this public website, its forms, or its assistant.
Public forms request business contact and workflow information only. The assistant checks messages for sensitive-data indicators and provides a warning instead of forwarding detected sensitive content to an optional AI provider.
4. Service authentication
Service credentials are stored as server environment variables rather than in browser code. When the production Convex backend is configured, site-to-service requests use a server-held bearer token. Client network identifiers are transformed with a keyed HMAC before transmission, and backend requests have a fixed timeout.
5. Application safeguards
Server routes validate required fields and accepted formats, detect sensitive patient-data indicators, limit assistant message length and history, normalize email addresses, return controlled public errors, and apply endpoint-specific request throttling. Assistant messages and replies are not persisted; optional OpenAI requests disable response storage. Deterministic assistant fallbacks remain available when the AI service is absent or fails, and production form routes fail closed when persistence is unavailable. Public errors do not expose service details, and these routes do not intentionally log message bodies.
6. Dependency and release controls
Changes are maintained in version control. The repository’s current CI workflow runs type and lint checks, a production build, API and browser tests, and localization and accessibility checks. Software dependencies and deployment configuration require separate ongoing review; publication of this policy does not represent that every possible vulnerability has been eliminated.
7. Incident response
Security reports are received through the contact below and evaluated using the verified facts available. If an event triggers a contractual or legal reporting duty, notice timing, content, and recipients will follow the applicable requirement. This public policy does not claim a completed incident-response audit or a particular response certification.
8. Responsible disclosure
Report a suspected vulnerability to the privacy email below with the affected URL, a clear description, reproduction steps, and non-sensitive evidence. Do not access other people’s data, disrupt service, use social engineering, demand payment, or publicly disclose an unresolved issue. We will acknowledge and prioritize good-faith reports as resources permit, but this policy does not promise a reward or safe harbor beyond applicable law.
9. User and customer responsibilities
Visitors must protect their devices and accounts, use the site lawfully, avoid sensitive submissions, and report suspected misuse. Prospective customers must separately evaluate deployment architecture, access roles, retention, integrations, backups, incident duties, and workforce practices before using any approved service with regulated data.
10. Limitations
No internet system is risk-free. This policy does not claim HIPAA certification, regulatory approval, ISO or SOC certification, a completed independent audit, penetration-test results, or a guaranteed data-residency location. Controls may change as the public site evolves.
11. Contact
Send security and responsible-disclosure reports to CareBridge HealthTech LLC using the privacy email below. Do not include protected health information, credentials, or unnecessary personal data in a report.
Company contact
CareBridge HealthTech LLC
Address: 816 Tuscan Road, Harker Heights, Texas 76548, USA