Security
Last updated August 28, 2026
Sevana stores protected health information for California residential care facilities. The architecture is HIPAA-ready and the operating posture is HIPAA-required: the controls below are on for every facility rather than offered as options.
What is on by default
- Scoped to your facility
- Operator requests are scoped to the active facility in the application, and database row-level security independently confines facility data to the signed-in user's membership and active facility.
- Tamper-evident audit log
- Recorded audit entries are hash-chained with SHA-256. The readiness check recomputes each stored hash among the 100 most recent entries visible to the active facility.
- Signed-in access
- Resident records are available only after sign-in. Access follows the facility membership or signed family authorization attached to the account.
- Encrypted in transit and at rest
- Traffic is encrypted between your devices and Sevana, and stored data is encrypted at rest by the hosting and database providers.
- Clinical records stay in the application
- Family portal invitations can include the resident name needed to identify the invitation. Clinical records and care notes are reviewed after sign-in.
Reporting a vulnerability
Do not open a public issue for a security finding. Write to info@sevanacare.com with a clear description, steps to reproduce, the components affected, and a suggested mitigation if you have one. We acknowledge within 2 business days and target a fix or mitigation within 30 days for high-severity findings (CVSS 7.0 and above).
If a finding involves resident health information, put HIPAA-relevant in the subject line. Those reports skip the normal queue and reach our privacy officer within 1 business day. We treat good-faith reports as coordinated disclosure and do not pursue legal action for compliant disclosure. We do not run a paid bounty program; credit is available on request after the fix ships.
What is in scope
The application and its deployment configuration, database migrations and row-level security policies, the mobile bundles, and the authentication boundary. Out of scope: development environments seeded with synthetic data, social engineering of Sevana staff or facility customers, physical security of facility devices, traffic flooding, and outdated dependencies with no exploit path against Sevana.
Related
How we handle information is in the privacy policy. Operators can ask for the current security summary before they sign; request it through request access.