Trust Center
Security Overview
This page describes the public marketing and assessment-intake website only. It is not a certification and does not extend to CareOS or any other product.
Server-side input validation on all public formsImplemented
Per-IP rate limiting on form submission endpointsImplemented
Security response headers (CSP, HSTS, X-Content-Type-Options, Referrer-Policy, Permissions-Policy)Implemented
Honeypot spam protection on public formsImplemented
Encryption in transit (HTTPS)In Progress
Durable database with encryption at restPlanned
Role-based access control for internal toolsPlanned
Multi-factor authentication for internal systemsPlanned
Centralized audit loggingPlanned
Independent penetration testNot Yet Audited
SOC 2 Type II observation periodNot Yet Audited